Home

Description

IBM Concert Software 1.0.0 through 1.1.0 uses cross-origin resource sharing (CORS) which could allow an attacker to carry out privileged actions as the domain name is not being limited to only trusted domains.

PUBLISHED Reserved 2025-03-10 | Published 2025-08-18 | Updated 2025-08-18 | Assigner ibm




MEDIUM: 5.4CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

Problem types

CWE-942 Permissive Cross-domain Policy with Untrusted Domains

Product status

Default status
unaffected

1.0.0
affected

References

www.ibm.com/support/pages/node/7242354 vendor-advisory patch

cve.org (CVE-2025-27909)

nvd.nist.gov (CVE-2025-27909)

Download JSON