Cross-Site Scripting Vulnerability in IBM Concert by IBM
CVE-2025-36153

6.1MEDIUM

Key Information:

Vendor

IBM

Status
Vendor
CVE Published:
20 November 2025

What is CVE-2025-36153?

IBM Concert versions 1.0.0 through 2.0.0 are vulnerable to a cross-site scripting (XSS) flaw that allows an unauthenticated attacker to inject arbitrary JavaScript code into the web interface. This manipulation can compromise the functionality of the application and may lead to the disclosure of user credentials within a trusted session. It is crucial for users to monitor this vulnerability and apply necessary patches to mitigate potential risks.

Affected Version(s)

Concert 1.0.0 <= 2.0.0

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-36153 : Cross-Site Scripting Vulnerability in IBM Concert by IBM