VYPR
High severity8.1NVD Advisory· Published Jun 30, 2026· Updated Jul 6, 2026

CVE-2025-36359

CVE-2025-36359

Description

IBM DevOps Automation 1.0.1 and IBM DevOps Loop 1.0.2 does not invalidate session IDs after expiration which could allow an authenticated user to impersonate another user on the system.

Affected products

4
  • cpe:2.3:a:ibm:devops_automation:1.0.1:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:ibm:devops_automation:1.0.1:*:*:*:*:*:*:*
    • (no CPE)range: <=1.0.1
  • IBM/Devops Loop2 versions
    cpe:2.3:a:ibm:devops_loop:1.0.2:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:ibm:devops_loop:1.0.2:*:*:*:*:*:*:*
    • (no CPE)range: <=1.0.2

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.