Unrated severityNVD Advisory· Published Jun 30, 2026· Updated Jul 1, 2026
IBM DevOps Loop is susceptible to an Insufficient Session Expiration vulnerability.
CVE-2025-36359
Description
IBM DevOps Automation 1.0.1 and IBM DevOps Loop 1.0.2 does not invalidate session IDs after expiration which could allow an authenticated user to impersonate another user on the system.
Affected products
2- Range: = 1.0.2
- Range: = 1.0.1
Patches
Vulnerability mechanics
References
1- www.ibm.com/support/pages/node/7277970mitrevendor-advisorypatch
News mentions
0No linked articles in our index yet.