Vulnerability Description
IBM DevOps Automation 1.0.1 and IBM DevOps Loop 1.0.2 does not invalidate session IDs after expiration which could allow an authenticated user to impersonate another user on the system.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ibm | Devops Automation | 1.0.1 |
| Ibm | Devops Loop | 1.0.2 |
Related Weaknesses (CWE)
References
- https://www.ibm.com/support/pages/node/7277970Vendor Advisory
FAQ
What is CVE-2025-36359?
CVE-2025-36359 is a vulnerability with a CVSS score of 8.1 (HIGH). IBM DevOps Automation 1.0.1 and IBM DevOps Loop 1.0.2 does not invalidate session IDs after expiration which could allow an authenticated user to impersonate another user on the system.
How severe is CVE-2025-36359?
CVE-2025-36359 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-36359?
Check the references section above for vendor advisories and patch information. Affected products include: Ibm Devops Automation, Ibm Devops Loop.