CVE-2025-36019: Multiple Vulnerabilities in IBM Concert Software.
IBM Concert 1.0.0 through 2.1.0 for Z hub framework is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Other sources
IBM Concert for Z hub framework is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
— IBM
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-36019?
CVE-2025-36019 is classified as a critical vulnerability due to its potential for exploitation through cross-site scripting.
How do I fix CVE-2025-36019?
To remediate CVE-2025-36019, upgrade IBM Concert Software to version 2.2.0 or later to mitigate the vulnerabilities.
Who is affected by CVE-2025-36019?
CVE-2025-36019 affects all versions of IBM Concert Software from 1.0.0 up to and including 2.1.0.
What type of vulnerability is CVE-2025-36019?
CVE-2025-36019 is a cross-site scripting vulnerability that allows attackers to inject arbitrary JavaScript code.
Can CVE-2025-36019 be exploited by authenticated users?
CVE-2025-36019 can be exploited by unauthenticated users, making it particularly dangerous.