CVE-2025-36222

8.7

IBM · Fusion

IBM Fusion products use insecure default configurations that expose AMQStreams without client authentication, potentially allowing unauthorized actions by remote attackers.

Executive summary

A critical vulnerability in IBM Fusion allows unauthenticated remote attackers to perform unauthorized actions due to insecure default configurations in AMQStreams.

Vulnerability

The flaw involves CWE-1188, where insecure default initialization of resources results in AMQStreams being exposed without requiring client authentication. This allows an unauthenticated attacker to interact with the message broker.

Business impact

The lack of authentication for AMQStreams poses a significant risk to data integrity and system operations. An attacker could potentially intercept, manipulate, or inject messages, leading to unauthorized control over system workflows and compromise of sensitive data. Given the CVSS score of 8.7, this vulnerability is classified as High severity and requires immediate attention to prevent potential service disruption or data breaches.

Remediation

Immediate Action: Upgrade to IBM Fusion, IBM Fusion HCI, or IBM Fusion HCI for watsonx version 2.11.0 as specified in the vendor security advisory.

Proactive Monitoring: Monitor network traffic for unusual connections to the AMQStreams interface and review system access logs for unauthorized attempts to interact with messaging services.

Compensating Controls: Implement strict network segmentation or firewall rules to restrict access to the AMQStreams interface to authorized management IP addresses only until the patch is deployed.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

This vulnerability presents a clear risk to the security of IBM Fusion environments by bypassing essential authentication controls. Security teams must prioritize the deployment of the version 2.11.0 update to remediate the insecure default configuration. Failure to patch these systems leaves the message bus exposed to potential unauthorized manipulation, which could have severe consequences for integrated applications and data pipelines.

More IBM CVEs

Sources

Originally found and disclosed by Robert Hotchkiss, per the CVE Program record.