← Back to CVE search

CVE-2025-36359

IBM DevOps Automation

Description

IBM DevOps Automation 1.0.1 and IBM DevOps Loop 1.0.2 does not invalidate session IDs after expiration which could allow an authenticated user to impersonate another user on the system.

CVSS 8.1EPSS 0.193%Risk 0.82
View source
Published
2026-06-30 21:16:30
Affected versions
==1.0.1
Type
Critical software
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N