Vulnerability Description
IBM Concert Software 1.0.0 through 1.1.0 uses cross-origin resource sharing (CORS) which could allow an attacker to carry out privileged actions as the domain name is not being limited to only trusted domains.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ibm | Concert | >= 1.0.0, < 2.0.0 |
Related Weaknesses (CWE)
References
- https://www.ibm.com/support/pages/node/7242354Vendor Advisory
FAQ
What is CVE-2025-27909?
CVE-2025-27909 is a vulnerability with a CVSS score of 5.4 (MEDIUM). IBM Concert Software 1.0.0 through 1.1.0 uses cross-origin resource sharing (CORS) which could allow an attacker to carry out privileged actions as the domain name is not being limited to only trusted...
How severe is CVE-2025-27909?
CVE-2025-27909 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-27909?
Check the references section above for vendor advisories and patch information. Affected products include: Ibm Concert.