CVE-2025-36149: IBM Concert Software clickjacking
IBM Concert Software 1.0.0 through 2.0.0 could allow a remote attacker to hijack the clicking action of the victim.
Other sources
IBM Concert Software could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim.
— IBM
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-36149?
CVE-2025-36149 has been classified as a medium severity vulnerability.
How do I fix CVE-2025-36149?
To remediate CVE-2025-36149, upgrade IBM Concert Software to version 2.0.1 or later.
What types of attacks can CVE-2025-36149 enable?
CVE-2025-36149 could allow attackers to hijack victims' click actions to launch further attacks.
Who is affected by CVE-2025-36149?
CVE-2025-36149 affects users of IBM Concert Software versions between 1.0.0 and 2.0.0 inclusive.
How does CVE-2025-36149 work?
CVE-2025-36149 exploits a vulnerability that allows a remote attacker to manipulate user click actions through a malicious website.