CVE-2025-36018

MEDIUM WAF: Low
CVSS 6.5 Published: 2026-02-17
CWE-352

IBM Concert 1.0.0 through 2.1.0 for Z hub componentĀ is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.

WAF Coverage Analysis

Cross-Site Request Forgery (CSRF) Low WAF Coverage

OWASP: A01:2021 Broken Access Control

Affected Software

VendorProductVersion
ibmconcert1.0.0 - 2.2.0

References

Back to CVE Database