CVE-2025-36363: Hcltech Devops Plan

High severity, CVSS 7.5. EPSS: 0.3% chance of exploitation in the next 30 days.

IBM DevOps Plan 3.0.0 through 3.0.5 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials.

Affected products

  • Hcltech Devops Plan: from 3.0.0, before 3.0.6 (fixed in 3.0.6)

Published 2026-03-03. Last modified 2026-07-27.