CVE-2025-36360 Details
Description
IBM UCD - IBM UrbanCode Deploy 7.1 through 7.1.2.27, 7.2 through 7.2.3.20, and 7.3 through 7.3.2.15 and IBM UCD - IBM DevOps Deploy 8.0 through 8.0.1.10, and 8.1 through 8.1.2.3 is susceptible to a race condition in http-session client-IP binding enforcement which may allow a session to be briefly reused from a new IP address before it is invalidated, potentially enabling unauthorized access under certain network conditions.
A race condition vulnerability has been identified in IBM UrbanCode Deploy versions 7.1 through 7.1.2.27, 7.2 through 7.2.3.20, and 7.3 through 7.3.2.15, as well as in IBM DevOps Deploy versions 8.0 through 8.0.1.10 and 8.1 through 8.1.2.3. This vulnerability arises from insufficient session expiration in the enforcement of client-IP binding for http sessions. It may allow a session to be temporarily reused from a different IP address before it is invalidated, potentially leading to unauthorized access under certain network conditions.
Users are advised to upgrade to IBM UrbanCode Deploy versions 7.1.2.28, 7.2.3.21, 7.3.2.16 or later, and to upgrade to IBM DevOps Deploy versions 8.0.1.11, 8.1.2.4, 8.2.0.0 or later.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Dec 15, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.ibm.com/support/pages/node/7254661 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-613 | Insufficient Session Expiration | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| ibm devops deploy | >= 8.0.0.0, < 8.0.1.11 >= 8.1.0.0, < 8.1.2.4 |
CPE
Remediation
| |
| ibm urbancode deploy | >= 7.1.0.0, < 7.1.2.28 >= 7.2.0.0, < 7.2.3.21 >= 7.3.0.0, < 7.3.2.16 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Dec 18, 2025 | Initial Analysis | [email protected] |
| Dec 15, 2025 | New CVE Received | [email protected] |