CVE-2025-36354

Severity
7.3HIGH
EPSS
0.1%
top 78.68%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 6

Description

IBM Security Verify Access and IBM Security Verify Access Docker 10.0.0.0 through 10.0.9.0 and 11.0.0.0 through 11.0.1.0 could allow an unauthenticated user to execute arbitrary commands with lower user privileges on the system due to improper validation of user supplied input.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:LExploitability: 3.9 | Impact: 3.4

Affected Packages6 packages

NVDibm/security_verify_access_docker10.0.0.010.0.9.0+1
CVEListV5ibm/security_verify_access_docker10.0.0.010.0.9.0 IF2+1
NVDibm/security_verify_access10.0.0.010.0.9.0+1
CVEListV5ibm/security_verify_access_appliance10.0.0.010.0.9.0 IF2+1
NVDibm/verify_identity_access_docker11.0.0.011.0.1.0+1

Patches

🔴Vulnerability Details

2
GHSA
GHSA-7jj8-xpmf-fcv4: IBM Security Verify Access and IBM Security Verify Access Docker 102025-10-06
CVEList
IBM Security Verify Access command execution2025-10-06
CVE-2025-36354 (HIGH CVSS 7.3) | IBM Security Verify Access and IBM | cvebase.io