Junglewise Threat Intelligence

CVE-2025-36359: IBM DevOps Automation and Loop insufficient session expiration

CVE-2025-36359 · Severity: high · CVSS 8.1 · Published 2026-06-30

Vendors: IBM.

Executive brief

IBM DevOps Automation and DevOps Loop are tools used to manage and automate software development workflows. A security flaw in these products fails to properly cancel user sessions after they should have expired. This could allow an authorized user to reuse an old session to impersonate another person on the system, potentially gaining access to sensitive code or administrative functions.

Technical details

An insufficient session expiration vulnerability (CWE-613) exists in IBM DevOps Automation version 1.0.1 and IBM DevOps Loop version 1.0.2. The application fails to properly invalidate session identifiers or authentication tokens once they have reached their expiration time. A remote attacker with low-level authenticated access can exploit this flaw to reuse expired session IDs, allowing them to impersonate other users and access protected resources. This vulnerability is exploitable over the network without user interaction. IBM recommends upgrading to IBM DevOps Loop version 1.0.3 to remediate the issue.

Affected products

  • IBM DevOps Automation 1.0.1
  • IBM DevOps Loop 1.0.2

Timeline

  • 2026-06-25: advisory: Initial publication by IBM
  • 2026-06-30: disclosed: NVD publication date

References