IBM Concert Cross-Site Request Forgery Vulnerability
Vulnerability
A cross-site request forgery (CSRF) vulnerability has been identified in the IBM Concert Z hub component, affecting versions 1.0.0 through 2.1.0. This vulnerability allows attackers to perform malicious and unauthorized actions by exploiting the trust that the application has in the user.
Impact
Exploitation of this vulnerability could lead to unauthorized actions being performed on behalf of a trusted user.
Remediation
Users are advised to upgrade to IBM Concert Software version 2.2.0. This version can be downloaded from the Container software library section of the IBM Entitled Registry (ICR) and users should follow the installation instructions provided for their type of deployment.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
