IBM Concert Software 1.0.0 through 1.1.0 uses cross-origin resource sharing (CORS) which could allow an attacker to carry out privileged actions as the domain name is not being limited to only trusted domains.
History

Mon, 18 Aug 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 18 Aug 2025 14:15:00 +0000

Type Values Removed Values Added
Description IBM Concert Software 1.0.0 through 1.1.0 uses cross-origin resource sharing (CORS) which could allow an attacker to carry out privileged actions as the domain name is not being limited to only trusted domains.
Title IBM Concert Software cross-origin resource sharing
First Time appeared Ibm
Ibm concert
Weaknesses CWE-942
CPEs cpe:2.3:a:ibm:concert:1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:concert:1.0.1:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm concert
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published: 2025-08-18T14:00:31.751Z

Updated: 2025-08-18T14:12:36.834Z

Reserved: 2025-03-10T17:14:11.136Z

Link: CVE-2025-27909

cve-icon Vulnrichment

Updated: 2025-08-18T14:12:26.833Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-08-18T14:15:28.550

Modified: 2025-08-18T20:16:28.750

Link: CVE-2025-27909

cve-icon Redhat

No data.