Cross-Site Request Forgery Vulnerability in IBM Concert Z Hub Component
CVE-2025-36018
6.5MEDIUM
What is CVE-2025-36018?
IBM Concert versions 1.0.0 through 2.1.0 for the Z hub component is susceptible to cross-site request forgery. This vulnerability may allow an attacker to carry out unapproved actions by exploiting the trust of an authenticated user on the website. If successfully executed, this could lead to unauthorized access or actions being performed within the application, putting sensitive information and system integrity at risk.
Affected Version(s)
Concert 1.0.0 <= 2.1.0