Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
6.1

IBM Concert Z Hub Framework: Unauthorized JavaScript Injection

CVE-2025-36019
Summary

IBM Concert versions 1.0.0 to 2.1.0 for the Z hub framework are open to a security risk where an unauthenticated attacker can inject malicious code into the web interface. This could allow them to potentially steal sensitive information from a trusted user session. We recommend updating to a fixed version of IBM Concert to protect against this risk.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versionsFix available
ibm concert > 1.0.0 , <= 2.2.0 –
Original title
IBM Concert 1.0.0 through 2.1.0 for Z hub framework is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thu...
Original description
IBM Concert 1.0.0 through 2.1.0 for Z hub framework is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
nvd CVSS3.1 6.1
Vulnerability type
CWE-79 Cross-site Scripting (XSS)
Published: 17 Feb 2026 · Updated: 11 Mar 2026 · First seen: 6 Mar 2026