« Volver al listado

CVE-2025-36360

Estado: AnalizadaMedia (5)—

IBM UCD - IBM UrbanCode Deploy 7.1 through 7.1.2.27, 7.2 through 7.2.3.20, and 7.3 through 7.3.2.15 and IBM UCD - IBM DevOps Deploy 8.0 through 8.0.1.10, and 8.1 through 8.1.2.3 is susceptible to a race condition in http-session client-IP binding enforcement which may allow a session to be briefly reused from a new IP address before it is invalidated, potentially enabling unauthorized access under certain network conditions.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-36360",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-36360",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-12-15T20:30:05.256376Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "psirt@us.ibm.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "LOW",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 3.4,
        "exploitabilityScore": 1.6
      }
    ]
  },
  "affected": [
    {
      "source": "psirt@us.ibm.com",
      "affectedData": [
        {
          "cpes": [
            "cpe:2.3:a:ibm:ucd___ibm_urbancode_deploy:7.1:*:*:*:*:*:*:*",
            "cpe:2.3:a:ibm:ucd___ibm_urbancode_deploy:7.1.2.27:*:*:*:*:*:*:*",
            "cpe:2.3:a:ibm:ucd___ibm_urbancode_deploy:7.2:*:*:*:*:*:*:*",
            "cpe:2.3:a:ibm:ucd___ibm_urbancode_deploy:7.2.3.20:*:*:*:*:*:*:*",
            "cpe:2.3:a:ibm:ucd___ibm_urbancode_deploy:7.3:*:*:*:*:*:*:*",
            "cpe:2.3:a:ibm:ucd___ibm_urbancode_deploy:7.3.2.15:*:*:*:*:*:*:*"
          ],
          "vendor": "IBM",
          "product": "UCD - IBM UrbanCode Deploy",
          "versions": [
            {
              "status": "affected",
              "version": "7.1",
              "versionType": "semver",
              "lessThanOrEqual": "7.1.2.27"
            },
            {
              "status": "affected",
              "version": "7.2",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.3.20"
            },
            {
              "status": "affected",
              "version": "7.3",
              "versionType": "semver",
              "lessThanOrEqual": "7.3.2.15"
            }
          ]
        },
        {
          "cpes": [
            "cpe:2.3:a:ibm:ucd___ibm_devops_deploy:8.0:*:*:*:*:*:*:*",
            "cpe:2.3:a:ibm:ucd___ibm_devops_deploy:8.0.1.10:*:*:*:*:*:*:*",
            "cpe:2.3:a:ibm:ucd___ibm_devops_deploy:8.1:*:*:*:*:*:*:*",
            "cpe:2.3:a:ibm:ucd___ibm_devops_deploy:8.1.2.3:*:*:*:*:*:*:*"
          ],
          "vendor": "IBM",
          "product": "UCD - IBM DevOps Deploy",
          "versions": [
            {
              "status": "affected",
              "version": "8.0",
              "versionType": "semver",
              "lessThanOrEqual": "8.0.1.10"
            },
            {
              "status": "affected",
              "version": "8.1",
              "versionType": "semver",
              "lessThanOrEqual": "8.1.2.3"
            }
          ]
        }
      ]
    }
  ],
  "published": "2025-12-15T20:15:50.237",
  "references": [
    {
      "url": "https://www.ibm.com/support/pages/node/7254661",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "psirt@us.ibm.com"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "psirt@us.ibm.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-613"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "IBM UCD - IBM UrbanCode Deploy 7.1 through 7.1.2.27, 7.2 through 7.2.3.20, and 7.3 through 7.3.2.15 and IBM UCD - IBM DevOps Deploy 8.0 through 8.0.1.10, and 8.1 through 8.1.2.3 is susceptible to a race condition in http-session client-IP binding enforcement which may allow a session to be briefly reused from a new IP address before it is invalidated, potentially enabling unauthorized access under certain network conditions."
    }
  ],
  "lastModified": "2026-06-17T09:14:40.083",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:ibm:devops_deploy:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "566A98BF-76EF-4D0F-9F18-B0EADEDC9FDE",
              "versionEndExcluding": "8.0.1.11",
              "versionStartIncluding": "8.0.0.0"
            },
            {
              "criteria": "cpe:2.3:a:ibm:devops_deploy:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "749B35C4-217A-4507-A9FB-85C7907D837B",
              "versionEndExcluding": "8.1.2.4",
              "versionStartIncluding": "8.1.0.0"
            },
            {
              "criteria": "cpe:2.3:a:ibm:urbancode_deploy:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "ECFA32A6-29C3-40DD-9D89-F496104E6DBD",
              "versionEndExcluding": "7.1.2.28",
              "versionStartIncluding": "7.1.0.0"
            },
            {
              "criteria": "cpe:2.3:a:ibm:urbancode_deploy:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "019C63D6-3DDA-432D-8D7D-62801E732796",
              "versionEndExcluding": "7.2.3.21",
              "versionStartIncluding": "7.2.0.0"
            },
            {
              "criteria": "cpe:2.3:a:ibm:urbancode_deploy:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B633DCF4-FB02-4081-A2E1-E38050C5EF04",
              "versionEndExcluding": "7.3.2.16",
              "versionStartIncluding": "7.3.0.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "psirt@us.ibm.com"
}