{"id":"CVE-2025-36363","title":"IBM DevOps Plan 3.0.0 through 3.0.5 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials.","summary":"IBM DevOps Plan 3.0.0 through 3.0.5 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials.","severity":"medium","cvss":5.9,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","cwe":["CWE-307"],"vendor":"hcltech","product":"devops_plan","affected":["devops_plan >= 3.0.0, < 3.0.6"],"patched":["devops_plan 3.0.6"],"published":"2026-03-03","updated":"2026-07-27","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-36363","references":[{"url":"https://www.ibm.com/support/pages/node/7261934","label":"psirt@us.ibm.com"}],"tags":["nvd"],"epss":0.00241,"epssPercentile":0.13593,"ingestedAt":"2026-07-27T18:22:57.662Z","slug":"CVE-2025-36363","body":"## Overview\n\nIBM DevOps Plan 3.0.0 through 3.0.5 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials.\n\n## Affected\n\n- `devops_plan >= 3.0.0, < 3.0.6`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `devops_plan 3.0.6`","depth":"sunlit","depthScore":32,"depthScoreParts":{"impact":32.5,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}