VYPR
Unrated severityNVD Advisory· Published Jun 30, 2026· Updated Jul 1, 2026

IBM DevOps Loop is susceptible to an Insufficient Session Expiration vulnerability.

CVE-2025-36359

Description

IBM DevOps Automation 1.0.1 and IBM DevOps Loop 1.0.2 does not invalidate session IDs after expiration which could allow an authenticated user to impersonate another user on the system.

Affected products

2

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.