CVE-2025-36222

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
11/09/2025
Last modified:
02/10/2025

Description

IBM Fusion 2.2.0 through 2.10.1, IBM Fusion HCI 2.2.0 through 2.10.0, and IBM Fusion HCI for watsonx 2.8.2 through 2.10.0 uses insecure default configurations that could expose AMQStreams without client authentication that could allow an attacker to perform unauthorized actions.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:ibm:storage_fusion:*:*:*:*:*:*:*:* 2.2.0 (including) 2.11.0 (excluding)
cpe:2.3:a:ibm:storage_fusion_hci:*:*:*:*:*:*:*:* 2.2.0 (including) 2.11.0 (excluding)
cpe:2.3:a:ibm:storage_fusion_hci_for_watsonx:*:*:*:*:*:*:*:* 2.8.2 (including) 2.11.0 (excluding)


References to Advisories, Solutions, and Tools