Server-Side Request Forgery Vulnerability in IBM Concert
CVE-2025-36243
5.4MEDIUM
What is CVE-2025-36243?
IBM Concert versions 1.0.0 through 2.1.0 contain a server-side request forgery vulnerability that could be exploited by an authenticated attacker. This flaw allows attackers to send unauthorized requests from the affected system, potentially enabling them to perform network enumeration or support other malicious actions. Organizations using these versions of IBM Concert should apply the necessary patches and take other mitigating steps to secure their systems.
Affected Version(s)
Concert 1.0.0 <= 2.1.0