High severity8.1NVD Advisory· Published Jun 30, 2026· Updated Jul 6, 2026
CVE-2025-36359
CVE-2025-36359
Description
IBM DevOps Automation 1.0.1 and IBM DevOps Loop 1.0.2 does not invalidate session IDs after expiration which could allow an authenticated user to impersonate another user on the system.
Affected products
4cpe:2.3:a:ibm:devops_automation:1.0.1:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:ibm:devops_automation:1.0.1:*:*:*:*:*:*:*
- (no CPE)range: <=1.0.1
cpe:2.3:a:ibm:devops_loop:1.0.2:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:ibm:devops_loop:1.0.2:*:*:*:*:*:*:*
- (no CPE)range: <=1.0.2
Patches
Vulnerability mechanics
References
1- www.ibm.com/support/pages/node/7277970nvdVendor Advisory
News mentions
0No linked articles in our index yet.