PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-36363 IBM CVE debrief

IBM DevOps Plan 3.0.0 through 3.0.5 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. The vulnerability affects IBM DevOps Plan versions 3.0.0 through 3.0.5, with a CVSS score of 5.9 and a severity of MEDIUM. Security teams should review and adjust account lockout settings, and consider upgrading to version 3.0.6 or later. Evidence is based on the official CVE record and NVD detail, which were published on 2026-03-03T20:16:43.120Z and have not been modified since then. The NVD entry is currently Analyzed, providing additional context for the vulnerability.

Vendor
IBM
Product
DevOps Plan
CVSS
MEDIUM 5.9
CISA KEV
Not listed in stored evidence
Original CVE published
2026-03-03
Original CVE updated
2026-07-27
Advisory published
2026-03-03
Advisory updated
2026-07-27

Who should care

Security teams should review IBM DevOps Plan 3.0.0 through 3.0.5 for inadequate account lockout settings and consider upgrading to version 3.0.6 or later.

Technical summary

The CVE-2025-36363 vulnerability affects IBM DevOps Plan versions 3.0.0 through 3.0.5. The CVSS score is 5.9 with a severity of MEDIUM. The vulnerability is related to an inadequate account lockout setting that could allow a remote attacker to brute force account credentials.

Defensive priority

Medium priority due to the potential for brute force attacks. Security teams should review and adjust account lockout settings, and consider upgrading to version 3.0.6 or later. Monitoring for suspicious login attempts is also recommended. Compensating controls for exposed systems should be reviewed while remediation is scheduled and verified. Relevant monitoring, detection, and logs for exposed assets should be checked for extra review. Affected product deployments in managed environments should be confirmed and an owner assigned for follow-up. The official advisory or CVE record should be reviewed to validate affected scope, severity, and vendor guidance. Vendor-supported updates or mitigations should be planned through normal change control where exposure is confirmed. Asset inventory and rollback/change windows should also be considered for exposed systems. Source tracking is necessary for affected systems. Exposure review and compensating controls should be implemented for systems that are not yet patched. Security teams should also review IBM DevOps Plan 3.0.0 through 3.0.5 for inadequate account lockout settings and consider upgrading to version 3.0.6 or later. The CVE-2025-36363 vulnerability affects IBM DevOps Plan versions 3.0.0 through 3.0.5. The CVSS score is 5.9 with a severity of MEDIUM. The vulnerability is related to an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM DevOps Plan 3.0.0 through 3.0.5 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. Security teams should review IBM DevOps Plan 3.0.0 through 3.0.5 for inadequate account lockout settings and consider upgrading to version 3.0.6 or later. The CVE record was published on 2026-03-03T20:16:43.120Z and has not been modified since then. The NVD entry is currently Analyzed. Evidence is based on the official CVE record and NVD detail. The CVE record was published on 2026-03-03T20:16:43.120Z and has not been modified since then. The NVD entry is currently Analyzed. The vulnerability affects IBM DevOps Plan versions 3.0.0 through 3.0.5, and the CVSS score is 5.9 with a 5

Recommended defensive actions

  • Review and adjust account lockout settings
  • Upgrade to IBM DevOps Plan version 3.0.6 or later
  • Monitor for suspicious login attempts

Evidence notes

Evidence is based on the official CVE record and NVD detail. The CVE record was published on 2026-03-03T20:16:43.120Z and has not been modified since then. The NVD entry is currently Analyzed. The vulnerability affects IBM DevOps Plan versions 3.0.0 through 3.0.5, and the CVSS score is 5.9 with a severity of MEDIUM. There is potential for brute force attacks due to inadequate account lockout settings.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-03-03T20:16:43.120Z and has not been modified since then. The NVD entry is currently Analyzed.