PT-2025-51282 · Ibm · Ibm Urbancode Deploy+1

Published

2025-12-15

·

Updated

2025-12-21

·

CVE-2025-36360

CVSS v3.1

5.0

Medium

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions IBM UrbanCode Deploy versions 7.1 through 7.1.2.27 IBM UrbanCode Deploy versions 7.2 through 7.2.3.20 IBM UrbanCode Deploy versions 7.3 through 7.3.2.15 IBM DevOps Deploy versions 8.0 through 8.0.1.10 IBM DevOps Deploy versions 8.1 through 8.1.2.3
Description The software contains a race condition in the http-session client-IP binding enforcement. This may allow a session to be briefly reused from a new IP address before it is invalidated, potentially enabling unauthorized access under certain network conditions.
Recommendations Update IBM UrbanCode Deploy to a version later than 7.1.2.27 Update IBM UrbanCode Deploy to a version later than 7.2.3.20 Update IBM UrbanCode Deploy to a version later than 7.3.2.15 Update IBM DevOps Deploy to a version later than 8.0.1.10 Update IBM DevOps Deploy to a version later than 8.1.2.3

Fix

Insufficient Session Expiration

Weakness Enumeration

Related Identifiers

CVE-2025-36360

Affected Products

Ibm Devops Deploy
Ibm Urbancode Deploy