IBM Fusion 2.2.0 through 2.10.1, IBM Fusion HCI 2.2.0 through 2.10.0, and IBM Fusion HCI for watsonx 2.8.2 through 2.10.0 uses insecure default configurations that could expose AMQStreams without client authentication that could allow an attacker to perform unauthorized actions.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://www.ibm.com/support/pages/node/7244646 |
![]() ![]() |
History
Fri, 12 Sep 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 11 Sep 2025 21:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | IBM Fusion 2.2.0 through 2.10.1, IBM Fusion HCI 2.2.0 through 2.10.0, and IBM Fusion HCI for watsonx 2.8.2 through 2.10.0 uses insecure default configurations that could expose AMQStreams without client authentication that could allow an attacker to perform unauthorized actions. | |
Title | IBM Fusion insecure default configuration | |
First Time appeared |
Ibm
Ibm storage Fusion Ibm storage Fusion Hci Ibm storage Fusion Hci For Watsonx |
|
Weaknesses | CWE-1188 | |
CPEs | cpe:2.3:a:ibm:storage_fusion:2.10.1:*:*:*:*:*:*:* cpe:2.3:a:ibm:storage_fusion:2.2.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:storage_fusion_hci:2.10.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:storage_fusion_hci:2.2.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:storage_fusion_hci_for_watsonx:2.10.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:storage_fusion_hci_for_watsonx:2.8.2:*:*:*:*:*:*:* |
|
Vendors & Products |
Ibm
Ibm storage Fusion Ibm storage Fusion Hci Ibm storage Fusion Hci For Watsonx |
|
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: ibm
Published: 2025-09-11T20:44:06.696Z
Updated: 2025-09-13T03:55:38.759Z
Reserved: 2025-04-15T21:16:41.802Z
Link: CVE-2025-36222

Updated: 2025-09-12T13:12:59.747Z

Status : Awaiting Analysis
Published: 2025-09-11T21:15:34.350
Modified: 2025-09-15T15:22:38.297
Link: CVE-2025-36222

No data.