CVE-2025-36364
Received Received - Intake
Local Cache Exposure in IBM DevOps Plan

Publication date: 2026-03-03

Last updated on: 2026-03-04

Assigner: IBM Corporation

Description
IBM DevOps Plan 3.0.0 through 3.0.5 allows web page cache to be stored locally which can be read by another user on the system.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-03-03
Last Modified
2026-03-04
Generated
2026-05-06
AI Q&A
2026-03-03
EPSS Evaluated
2026-05-05
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
ibm devops_plan From 3.0.0 (inc) to 3.0.6 (exc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-525 The web application does not use an appropriate caching policy that specifies the extent to which each web page and associated form fields should be cached.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

The IBM DevOps Plan versions 3.0.0 through 3.0.5 have a vulnerability where sensitive data is transmitted via request query parameters and cached locally by the web browser.

This cached data can then be accessed by other users on the same system, potentially exposing sensitive information.

This issue is classified under CWE-525: Use of Web Browser Cache Containing Sensitive Information.


How can this vulnerability impact me? :

This vulnerability can lead to unauthorized disclosure of sensitive information because cached web page data containing sensitive details can be read by other users on the same system.

Since the attack vector is local with low complexity and no privileges or user interaction required, an attacker with access to the same system could easily exploit this to gain confidential information.

The confidentiality impact is high, but there is no impact on integrity or availability.


How does this vulnerability affect compliance with common standards and regulations (like GDPR, HIPAA)?:

I don't know


How can this vulnerability be detected on my network or system? Can you suggest some commands?

I don't know


What immediate steps should I take to mitigate this vulnerability?

The vulnerability in IBM DevOps Plan versions 3.0.0 through 3.0.5 can be remediated by upgrading to version 3.0.6.

No workarounds or mitigations are provided other than the upgrade.

Customers are advised to assess the impact in their environments and subscribe to IBM notifications for future security alerts.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart