CVE-2025-36359EPSS p23.7%
CVE-2025-36359CVE-2025-36359
ibm / devops_automation
Description
IBM DevOps Automation 1.0.1 and IBM DevOps Loop 1.0.2 does not invalidate session IDs after expiration which could allow an authenticated user to impersonate another user on the system.
Scoring
| CVSS | 8.1 () |
| Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N |
| EPSS | 0.33% probability of exploitation · percentile 23.7% · 2026-10-05T12:00:23Z |
| Last modified | 2026-09-30 |