PatchSiren cyber security CVE debrief
CVE-2025-36363 IBM CVE debrief
IBM DevOps Plan 3.0.0 through 3.0.5 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. The vulnerability affects IBM DevOps Plan versions 3.0.0 through 3.0.5, with a CVSS score of 5.9 and a severity of MEDIUM. Security teams should review and adjust account lockout settings, and consider upgrading to version 3.0.6 or later. Evidence is based on the official CVE record and NVD detail, which were published on 2026-03-03T20:16:43.120Z and have not been modified since then. The NVD entry is currently Analyzed, providing additional context for the vulnerability.
- Vendor
- IBM
- Product
- DevOps Plan
- CVSS
- MEDIUM 5.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-03-03
- Original CVE updated
- 2026-07-27
- Advisory published
- 2026-03-03
- Advisory updated
- 2026-07-27
Who should care
Security teams should review IBM DevOps Plan 3.0.0 through 3.0.5 for inadequate account lockout settings and consider upgrading to version 3.0.6 or later.
Technical summary
The CVE-2025-36363 vulnerability affects IBM DevOps Plan versions 3.0.0 through 3.0.5. The CVSS score is 5.9 with a severity of MEDIUM. The vulnerability is related to an inadequate account lockout setting that could allow a remote attacker to brute force account credentials.
Defensive priority
Medium priority due to the potential for brute force attacks. Security teams should review and adjust account lockout settings, and consider upgrading to version 3.0.6 or later. Monitoring for suspicious login attempts is also recommended. Compensating controls for exposed systems should be reviewed while remediation is scheduled and verified. Relevant monitoring, detection, and logs for exposed assets should be checked for extra review. Affected product deployments in managed environments should be confirmed and an owner assigned for follow-up. The official advisory or CVE record should be reviewed to validate affected scope, severity, and vendor guidance. Vendor-supported updates or mitigations should be planned through normal change control where exposure is confirmed. Asset inventory and rollback/change windows should also be considered for exposed systems. Source tracking is necessary for affected systems. Exposure review and compensating controls should be implemented for systems that are not yet patched. Security teams should also review IBM DevOps Plan 3.0.0 through 3.0.5 for inadequate account lockout settings and consider upgrading to version 3.0.6 or later. The CVE-2025-36363 vulnerability affects IBM DevOps Plan versions 3.0.0 through 3.0.5. The CVSS score is 5.9 with a severity of MEDIUM. The vulnerability is related to an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM DevOps Plan 3.0.0 through 3.0.5 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. Security teams should review IBM DevOps Plan 3.0.0 through 3.0.5 for inadequate account lockout settings and consider upgrading to version 3.0.6 or later. The CVE record was published on 2026-03-03T20:16:43.120Z and has not been modified since then. The NVD entry is currently Analyzed. Evidence is based on the official CVE record and NVD detail. The CVE record was published on 2026-03-03T20:16:43.120Z and has not been modified since then. The NVD entry is currently Analyzed. The vulnerability affects IBM DevOps Plan versions 3.0.0 through 3.0.5, and the CVSS score is 5.9 with a 5
Recommended defensive actions
- Review and adjust account lockout settings
- Upgrade to IBM DevOps Plan version 3.0.6 or later
- Monitor for suspicious login attempts
Evidence notes
Evidence is based on the official CVE record and NVD detail. The CVE record was published on 2026-03-03T20:16:43.120Z and has not been modified since then. The NVD entry is currently Analyzed. The vulnerability affects IBM DevOps Plan versions 3.0.0 through 3.0.5, and the CVSS score is 5.9 with a severity of MEDIUM. There is potential for brute force attacks due to inadequate account lockout settings.
Official resources
-
CVE-2025-36363 CVE record
CVE.org
-
CVE-2025-36363 NVD detail
NVD
-
Source item URL
nvd_modified
-
Mitigation or vendor reference
[email protected] - Vendor Advisory
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-03-03T20:16:43.120Z and has not been modified since then. The NVD entry is currently Analyzed.