← Back

CVE-2025-36359

nvd nist
Published: Jun 30, 2026Modified: Jul 6, 2026

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Exploitability: 2.8 / Impact: 3.6
Source: NVD

Description

IBM DevOps Automation 1.0.1 and IBM DevOps Loop 1.0.2 does not invalidate session IDs after expiration which could allow an authenticated user to impersonate another user on the system.

Affected (2)

2 products
Devops Automation
Devops Loop
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Version 1.0.1
Version 1.0.2

References (1)

Source: psirt@us.ibm.com
Vendor Advisory

Timeline

No history available yet.