CVE-2025-36364
IBM DevOps Plan 3.0.0 through 3.0.5 allows web page cache to be stored locally which can be read by another user on the system.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.2
- CVSS vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS probability
- 0.10%
- CWE
- CWE-525
- Published
- 2026-03-03
- Last modified
- 2026-03-13
Affected products
- IBM DevOps Plan
Weakness type
Related vulnerabilities
- CVE-2026-13697 — undici vulnerable to cross-user information disclosure and parse-time crash via degenerate private cache directives
- CVE-2024-23571 — HCL Aftermarket EPC is vulnerable to attack since the application does not have an appropriate...
- CVE-2026-41918 — A vulnerability has been identified in RUGGEDCOM RST2428P (6GK6242-6PA00) (All versions < V4.0)....
- CVE-2026-41322 — @astrojs/node: Cache Poisoning due to incorrect error handling when if-match header is malformed
- CVE-2025-15554 — Admin Passwords Cached by Browsers in Truesec LAPSWebUI
- CVE-2026-27514 — Tenda F3 Plaintext Credential Exposure in Configuration Download
- CVE-2026-24437 — Tenda W30E V2 Missing Cache Controls for Credential-bearing Pages
- CVE-2025-52659 — HCL AION is affected by a Cacheable HTTP Response vulnerability