CVE-2025-36018: Multiple Vulnerabilities in IBM Concert Software.
IBM Concert 1.0.0 through 2.1.0 for Z hub component is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
Other sources
IBM Concert for Z hub component is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
— IBM
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-36018?
CVE-2025-36018 is classified as a high severity vulnerability due to its potential for cross-site request forgery attacks.
How do I fix CVE-2025-36018?
To fix CVE-2025-36018, upgrade IBM Concert Software to version 2.2.0 or higher.
What are the consequences of exploiting CVE-2025-36018?
Exploiting CVE-2025-36018 could allow an attacker to perform unauthorized actions on behalf of an authenticated user.
Which versions of IBM Concert Software are affected by CVE-2025-36018?
CVE-2025-36018 affects IBM Concert Software versions 1.0.0 through 2.1.0.
Is there a temporary workaround for CVE-2025-36018?
Currently, there is no official temporary workaround available for CVE-2025-36018.