Junglewise Threat Intelligence

CVE-2025-36364: IBM DevOps Plan sensitive information disclosure in web cache

CVE-2025-36364 · Severity: medium · CVSS 6.2 · Published 2026-03-03

Technologies: IBM DevOps Plan. Vendors: IBM.

Executive brief

IBM DevOps Plan, a tool used for managing software development lifecycles, contains a security flaw where sensitive information is stored in a local web cache. This could allow an unauthorized person with access to the same computer system to view private data or credentials belonging to another user. Organizations should update to the latest version to ensure sensitive data is not inadvertently exposed on shared workstations or servers.

Technical details

IBM DevOps Plan (versions 3.0.0 through 3.0.5) is vulnerable to sensitive information disclosure due to improper cache management (CWE-525). The application allows sensitive data, including information transmitted via REST API request query parameters, to be stored in the local web browser cache. An attacker with local access to the system can retrieve and read this cached data, potentially gaining access to sensitive user information or session details. The vulnerability is exploited locally without requiring special privileges or user interaction. IBM has released version 3.0.6 to remediate this issue.

Affected products

  • IBM DevOps Plan 3.0.0 - 3.0.5

Timeline

  • 2026-02-26: advisory: Initial publication by IBM
  • 2026-03-03: disclosed: NVD publication date
  • 2026-03-03: patched: Remediation via version 3.0.6 identified

References

Related threats