Skip to main content

Vendor/product archive

ibm / devops_plan CVEs

Beta · best-effort

3 CVEs tagged to ibm / devops_plan0 Critical, 0 High, 3 Medium, 0 Low, 0 Unrated.

CVE-2026-4096

Published Jun 11, 2026

IBM DevOps Plan 3.0.0 through 3.0.6 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct var…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-36364

Published Mar 3, 2026

IBM DevOps Plan 3.0.0 through 3.0.5 allows web page cache to be stored locally which can be read by another user on the system.

CVSS 6.2 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-36363

Published Mar 3, 2026

IBM DevOps Plan 3.0.0 through 3.0.5 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials.

CVSS 5.9 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 1-3 of 3 CVEsPage 1 of 1