← Back

CVE-2025-36354

nvd nist
Published: Oct 6, 2025Modified: Jun 17, 2026

JSON object

Loading...
7.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Exploitability: 3.9 / Impact: 3.4
Source: psirt@us.ibm.com (Secondary)

Description

IBM Security Verify Access and IBM Security Verify Access Docker 10.0.0.0 through 10.0.9.0 and 11.0.0.0 through 11.0.1.0 could allow an unauthenticated user to execute arbitrary commands with lower user privileges on the system due to improper validation of user supplied input.

Affected (12)

4 products
Security Verify Access
Security Verify Access Docker
Verify Identity Access
Verify Identity Access Docker
Configuration A
8 vulnerable
Vulnerable SoftwareAffected Versions
Ibm
From 10.0.0.0 to 10.0.9.0
Version 10.0.9.0
Version 10.0.9.0 interim_fix1
Version 10.0.9.0 interim_fix2
Ibm
From 10.0.0.0 to 10.0.9.0
Version 10.0.9.0
Version 10.0.9.0 interim_fix1
Version 10.0.9.0 interim_fix2
Configuration B
4 vulnerable
Vulnerable SoftwareAffected Versions
Ibm
From 11.0.0.0 to 11.0.1.0
Version 11.0.1.0
Ibm
From 11.0.0.0 to 11.0.1.0
Version 11.0.1.0

References (1)

Source: psirt@us.ibm.com
PatchVendor Advisory

Timeline

No history available yet.