Description

IBM UCD - IBM UrbanCode Deploy 7.1 through 7.1.2.27, 7.2 through 7.2.3.20, and 7.3 through 7.3.2.15 and IBM UCD - IBM DevOps Deploy 8.0 through 8.0.1.10, and 8.1 through 8.1.2.3 is susceptible to a race condition in http-session client-IP binding enforcement which may allow a session to be briefly reused from a new IP address before it is invalidated, potentially enabling unauthorized access under certain network conditions.

INFO

Published Date :

2025-12-15T19:38:57.832Z

Last Modified :

2025-12-15T20:30:18.476Z

Source :

ibm
AFFECTED PRODUCTS

The following products are affected by CVE-2025-36360 vulnerability.

Vendors Products
Ibm
  • Ucd Ibm Devops Deploy
  • Ucd Ibm Urbancode Deploy
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2025-36360.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact