IBM Fusion and IBM Fusion HCI Insecure Default Configuration Vulnerability Allowing Unauthorized Actions

Vulnerability

A vulnerability exists in IBM Fusion versions 2.2.0 through 2.10.1, IBM Fusion HCI versions 2.2.0 through 2.10.0, and IBM Fusion HCI for watsonx versions 2.8.2 through 2.10.0. These versions use insecure default configurations that could expose AMQStreams without client authentication, potentially allowing an attacker to perform unauthorized actions.

Impact

Exploitation of this vulnerability could lead to unauthorized actions being performed on AMQStreams, due to the lack of client authentication.

Remediation

Users are advised to upgrade to IBM Fusion 2.11.0, IBM Fusion HCI 2.11.0, or IBM Fusion HCI for watsonx 2.11.0. Instructions for upgrading can be found in the respective product README files.

Added: Sep 11, 2025, 9:20 PM
Updated: Sep 11, 2025, 9:20 PM

Vulnerability Rating

Custom Algorithm
spread
0.3
impact
1.3
exploitability
7.0
remediation
7.7
relevance
0.5
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.