CVE-2025-36363: IBM DevOps Plan is vulnerable to Excessive Authentication Attempts
IBM DevOps Plan 3.0.0 through 3.0.5 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials.
Other sources
IBM DevOps Plan uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM DevOps Planto a version that resolves this vulnerability.Fixed in 3.0.6
Event History
Frequently Asked Questions
What is the severity of CVE-2025-36363?
The severity of CVE-2025-36363 is high with a score of 7.5.
How do I fix CVE-2025-36363?
To fix CVE-2025-36363, ensure that you configure adequate account lockout settings in IBM DevOps Plan.
What systems are affected by CVE-2025-36363?
CVE-2025-36363 affects IBM DevOps Plan versions 3.0.0 through 3.0.5.
What kind of attack does CVE-2025-36363 permit?
CVE-2025-36363 allows a remote attacker to perform brute force attacks on account credentials.
Is CVE-2025-36363 an authentication vulnerability?
Yes, CVE-2025-36363 is classified as an excessive authentication attempts vulnerability.