CVE-2025-36243: Multiple Vulnerabilities in IBM Concert Software.
IBM Concert 1.0.0 through 2.1.0 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.
Other sources
IBM Concert Software is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.
— IBM
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-36243?
CVE-2025-36243 is considered a high severity vulnerability due to its potential for server-side request forgery, leading to unauthorized requests.
How do I fix CVE-2025-36243?
To mitigate CVE-2025-36243, upgrade IBM Concert Software to version 2.2.0 or later to address the SSRF vulnerabilities.
Who is affected by CVE-2025-36243?
CVE-2025-36243 affects users of IBM Concert Software versions 1.0.0 through 2.1.0.
What types of attacks can CVE-2025-36243 facilitate?
CVE-2025-36243 can facilitate network enumeration and other unauthorized attacks by allowing authenticated attackers to send unauthorized requests.
Is authentication required to exploit CVE-2025-36243?
Yes, CVE-2025-36243 requires authentication, allowing only authenticated attackers to exploit the server-side request forgery vulnerability.