HIGH · 8.7

CVE-2025-36222

IBM Fusion 2.2.0 through 2.10.1, IBM Fusion HCI 2.2.0 through 2.10.0, and IBM Fusion HCI for watsonx 2.8.2 through 2.10.0 uses insecure default configurations that could expose AMQStreams without clie...

Vulnerability Description

IBM Fusion 2.2.0 through 2.10.1, IBM Fusion HCI 2.2.0 through 2.10.0, and IBM Fusion HCI for watsonx 2.8.2 through 2.10.0 uses insecure default configurations that could expose AMQStreams without client authentication that could allow an attacker to perform unauthorized actions.

CVSS Score

8.7

HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
CHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
NONE

Affected Products

VendorProductVersions
IbmStorage Fusion>= 2.2.0, < 2.11.0
IbmStorage Fusion Hci>= 2.2.0, < 2.11.0
IbmStorage Fusion Hci For Watsonx>= 2.8.2, < 2.11.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2025-36222?

CVE-2025-36222 is a vulnerability with a CVSS score of 8.7 (HIGH). IBM Fusion 2.2.0 through 2.10.1, IBM Fusion HCI 2.2.0 through 2.10.0, and IBM Fusion HCI for watsonx 2.8.2 through 2.10.0 uses insecure default configurations that could expose AMQStreams without clie...

How severe is CVE-2025-36222?

CVE-2025-36222 has been rated HIGH with a CVSS base score of 8.7/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2025-36222?

Check the references section above for vendor advisories and patch information. Affected products include: Ibm Storage Fusion, Ibm Storage Fusion Hci, Ibm Storage Fusion Hci For Watsonx.