Executive brief
IBM DevOps Plan, a tool used for managing software development lifecycles, contains a security flaw in its login mechanism. The software does not properly lock accounts after multiple failed login attempts, which could allow an attacker to guess user passwords through automated trial-and-error. If successful, an attacker could gain unauthorized access to the development environment and sensitive project data.
Technical details
IBM DevOps Plan is vulnerable to improper restriction of excessive authentication attempts (CWE-307). The vulnerability exists because the account lockout settings are inadequately configured, failing to prevent automated brute-force attacks against user credentials. A remote, unauthenticated attacker can exploit this by repeatedly attempting to authenticate with different passwords for a known username. While the attack complexity is rated as high (likely due to the time required for brute-forcing or specific environmental configurations), a successful exploit results in unauthorized access to the platform. Users are advised to upgrade to version 3.0.6 to remediate the issue.
Affected products
- IBM DevOps Plan 3.0.0 - 3.0.5
Timeline
- 2026-02-26: advisory: Initial publication by IBM
- 2026-03-03: disclosed: NVD publication date
- 2026-03-03: patched: Fix available in version 3.0.6