CVE-2025-36360

IBM UCD - IBM UrbanCode Deploy 7.1 through 7.1.2.27, 7.2 through 7.2.3.20, and 7.3 through 7.3.2.15 and IBM UCD - IBM DevOps Deploy 8.0 through 8.0.1.10, and 8.1 through 8.1.2.3 is susceptible to a race condition in http-session client-IP binding enforcement which may allow a session to be briefly reused from a new IP address before it is invalidated, potentially enabling unauthorized access under certain network conditions.
References
Link Resource
https://www.ibm.com/support/pages/node/7254661 Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:ibm:devops_deploy:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:devops_deploy:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:urbancode_deploy:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:urbancode_deploy:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:urbancode_deploy:*:*:*:*:*:*:*:*

History

18 Dec 2025, 18:00

Type Values Removed Values Added
CPE cpe:2.3:a:ibm:devops_deploy:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:urbancode_deploy:*:*:*:*:*:*:*:*
First Time Ibm urbancode Deploy
Ibm
Ibm devops Deploy
References () https://www.ibm.com/support/pages/node/7254661 - () https://www.ibm.com/support/pages/node/7254661 - Vendor Advisory

15 Dec 2025, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-15 20:15

Updated : 2025-12-18 18:00


NVD link : CVE-2025-36360

Mitre link : CVE-2025-36360

CVE.ORG link : CVE-2025-36360


JSON object : View

Products Affected

ibm

  • devops_deploy
  • urbancode_deploy
CWE
CWE-613

Insufficient Session Expiration