IBM Fusion and IBM Fusion HCI Insecure Network Connection Vulnerability

Vulnerability

A vulnerability exists in IBM Fusion and IBM Fusion HCI versions 2.3.0 through 2.8.2, allowing an attacker with access to a Fusion container to establish an external network connection. This issue arises from improper restriction of communication channels, enabling unauthorized data egress.

Impact

Exploitation of this vulnerability could lead to unauthorized external network connections from within a Fusion container, allowing for potential data exfiltration or communication with external malicious entities.

Remediation

Users are advised to upgrade to version 2.9.0. Instructions for upgrading can be found in the IBM Fusion README and the IBM Fusion HCI README.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.3
impact
0.0
exploitability
4.9
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.