CVE-2025-36222

IBM Fusion 2.2.0 through 2.10.1, IBM Fusion HCI 2.2.0 through 2.10.0, and IBM Fusion HCI for watsonx 2.8.2 through 2.10.0 uses insecure default configurations that could expose AMQStreams without client authentication that could allow an attacker to perform unauthorized actions.
References
Link Resource
https://www.ibm.com/support/pages/node/7244646 Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:ibm:storage_fusion:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:storage_fusion_hci:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:storage_fusion_hci_for_watsonx:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-09-11 21:15

Updated : 2025-10-02 19:31


NVD link : CVE-2025-36222

Mitre link : CVE-2025-36222

CVE.ORG link : CVE-2025-36222


JSON object : View

Products Affected

ibm

  • storage_fusion_hci
  • storage_fusion_hci_for_watsonx
  • storage_fusion
CWE
CWE-1188

Initialization of a Resource with an Insecure Default