CVE-2025-36085: Multiple Vulnerabilities in IBM Concert Software.
IBM Concert 1.0.0 through 2.0.0 Software is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-36085?
CVE-2025-36085 has a severity rating that indicates it poses a serious risk due to the potential for server-side request forgery (SSRF) attacks.
How do I fix CVE-2025-36085?
To fix CVE-2025-36085, update IBM Concert Software to a version beyond 2.0.0 as per the vendor's guidelines.
Who is affected by CVE-2025-36085?
CVE-2025-36085 affects users of IBM Concert Software versions 1.0.0 through 2.0.0.
What can an attacker do with CVE-2025-36085?
An attacker can exploit CVE-2025-36085 to perform unauthorized server-side requests, which may lead to network enumeration or other attack vectors.
Is CVE-2025-36085 an authenticated vulnerability?
Yes, CVE-2025-36085 requires an authenticated attacker to exploit the vulnerability.