CVE-2025-36222

IBM Fusion 2.2.0 through 2.10.1, IBM Fusion HCI 2.2.0 through 2.10.0, and IBM Fusion HCI for watsonx 2.8.2 through 2.10.0 uses insecure default configurations that could expose AMQStreams without client authentication that could allow an attacker to perform unauthorized actions.
References
Link Resource
https://www.ibm.com/support/pages/node/7244646 Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:ibm:storage_fusion:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:storage_fusion_hci:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:storage_fusion_hci_for_watsonx:*:*:*:*:*:*:*:*

History

02 Oct 2025, 19:31

Type Values Removed Values Added
First Time Ibm storage Fusion Hci
Ibm
Ibm storage Fusion Hci For Watsonx
Ibm storage Fusion
References () https://www.ibm.com/support/pages/node/7244646 - () https://www.ibm.com/support/pages/node/7244646 - Vendor Advisory
CPE cpe:2.3:a:ibm:storage_fusion:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:storage_fusion_hci:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:storage_fusion_hci_for_watsonx:*:*:*:*:*:*:*:*

11 Sep 2025, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-09-11 21:15

Updated : 2025-10-02 19:31


NVD link : CVE-2025-36222

Mitre link : CVE-2025-36222

CVE.ORG link : CVE-2025-36222


JSON object : View

Products Affected

ibm

  • storage_fusion_hci
  • storage_fusion
  • storage_fusion_hci_for_watsonx
CWE
CWE-1188

Insecure Default Initialization of Resource