CVE-2025-36364: IBM DevOps Plan REST APIs are vulnerable to exposure of sensitive data through request query parameters.
IBM DevOps Plan 3.0.0 through 3.0.5 allows web page cache to be stored locally which can be read by another user on the system.
Other sources
IBM DevOps Plan allows web page cache to be stored locally which can be read by another user on the system.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM DevOps Planto a version that resolves this vulnerability.Fixed in 3.0.6Patch node/7253954
Event History
Frequently Asked Questions
What is the severity of CVE-2025-36364?
CVE-2025-36364 has been classified with a medium severity level due to the potential exposure of sensitive data.
How do I fix CVE-2025-36364?
To fix CVE-2025-36364, upgrade IBM DevOps Plan to version 3.0.6 or later to prevent the local storage of sensitive data.
Who is affected by CVE-2025-36364?
CVE-2025-36364 affects users of IBM DevOps Plan versions 3.0.0 through 3.0.5.
What kind of data is exposed in CVE-2025-36364?
CVE-2025-36364 can expose sensitive data through request query parameters stored in the local web page cache.
Is CVE-2025-36364 a local or remote vulnerability?
CVE-2025-36364 is considered a local vulnerability, as the exposed data can be accessed by other users on the same system.