Junglewise Threat Intelligence

CVE-2025-36363: IBM DevOps Plan brute force vulnerability in authentication

CVE-2025-36363 · Severity: medium · CVSS 5.9 · Published 2026-03-03

Technologies: IBM DevOps Plan. Vendors: IBM.

Executive brief

IBM DevOps Plan, a tool used for managing software development lifecycles, contains a security flaw in its login mechanism. The software does not properly lock accounts after multiple failed login attempts, which could allow an attacker to guess user passwords through automated trial-and-error. If successful, an attacker could gain unauthorized access to the development environment and sensitive project data.

Technical details

IBM DevOps Plan is vulnerable to improper restriction of excessive authentication attempts (CWE-307). The vulnerability exists because the account lockout settings are inadequately configured, failing to prevent automated brute-force attacks against user credentials. A remote, unauthenticated attacker can exploit this by repeatedly attempting to authenticate with different passwords for a known username. While the attack complexity is rated as high (likely due to the time required for brute-forcing or specific environmental configurations), a successful exploit results in unauthorized access to the platform. Users are advised to upgrade to version 3.0.6 to remediate the issue.

Affected products

  • IBM DevOps Plan 3.0.0 - 3.0.5

Timeline

  • 2026-02-26: advisory: Initial publication by IBM
  • 2026-03-03: disclosed: NVD publication date
  • 2026-03-03: patched: Fix available in version 3.0.6

References

Related threats