CVE-2025-36364
Received Received - Intake
Local Cache Exposure in IBM DevOps Plan

Publication date: 2026-03-03

Last updated on: 2026-03-04

Assigner: IBM Corporation

Description
IBM DevOps Plan 3.0.0 through 3.0.5 allows web page cache to be stored locally which can be read by another user on the system.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-03-03
Last Modified
2026-03-04
Generated
2026-06-16
AI Q&A
2026-03-03
EPSS Evaluated
2026-06-14
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
ibm devops_plan From 3.0.0 (inc) to 3.0.6 (exc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-525 The web application does not use an appropriate caching policy that specifies the extent to which each web page and associated form fields should be cached.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

The IBM DevOps Plan versions 3.0.0 through 3.0.5 have a vulnerability where sensitive data is transmitted via request query parameters and cached locally by the web browser.

This cached data can then be accessed by other users on the same system, potentially exposing sensitive information.

This issue is classified under CWE-525: Use of Web Browser Cache Containing Sensitive Information.

Impact Analysis

This vulnerability can lead to unauthorized disclosure of sensitive information because cached web page data containing sensitive details can be read by other users on the same system.

Since the attack vector is local with low complexity and no privileges or user interaction required, an attacker with access to the same system could easily exploit this to gain confidential information.

The confidentiality impact is high, but there is no impact on integrity or availability.

Compliance Impact

I don't know

Detection Guidance

I don't know

Mitigation Strategies

The vulnerability in IBM DevOps Plan versions 3.0.0 through 3.0.5 can be remediated by upgrading to version 3.0.6.

No workarounds or mitigations are provided other than the upgrade.

Customers are advised to assess the impact in their environments and subscribe to IBM notifications for future security alerts.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-36364. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart