{"id":"CVE-2025-36364","title":"IBM DevOps Plan 3.0.0 through 3.0.5 allows web page cache to be stored locally which can be read by another user on the system.","summary":"IBM DevOps Plan 3.0.0 through 3.0.5 allows web page cache to be stored locally which can be read by another user on the system.","severity":"medium","cvss":6.2,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","cwe":["CWE-525"],"vendor":"hcltech","product":"devops_plan","affected":["devops_plan >= 3.0.0, < 3.0.6"],"patched":["devops_plan 3.0.6"],"published":"2026-03-03","updated":"2026-07-27","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-36364","references":[{"url":"https://www.ibm.com/support/pages/node/7261930","label":"psirt@us.ibm.com"}],"tags":["nvd"],"epss":0.00104,"epssPercentile":0.01138,"ingestedAt":"2026-07-27T18:22:57.690Z","slug":"CVE-2025-36364","body":"## Overview\n\nIBM DevOps Plan 3.0.0 through 3.0.5 allows web page cache to be stored locally which can be read by another user on the system.\n\n## Affected\n\n- `devops_plan >= 3.0.0, < 3.0.6`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `devops_plan 3.0.6`","depth":"sunlit","depthScore":34,"depthScoreParts":{"impact":34.1,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}