IBM Concert Cross-Site Request Forgery Vulnerability

Vulnerability

A cross-site request forgery (CSRF) vulnerability has been identified in the IBM Concert Z hub component, affecting versions 1.0.0 through 2.1.0. This vulnerability allows attackers to perform malicious and unauthorized actions by exploiting the trust that the application has in the user.

Impact

Exploitation of this vulnerability could lead to unauthorized actions being performed on behalf of a trusted user.

Remediation

Users are advised to upgrade to IBM Concert Software version 2.2.0. This version can be downloaded from the Container software library section of the IBM Entitled Registry (ICR) and users should follow the installation instructions provided for their type of deployment.

Added: Feb 17, 2026, 7:46 PM
Updated: Feb 17, 2026, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
6.2
remediation
0.0
relevance
3.1
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.