IBM Security Verify Access and IBM Security Verify Access Docker 10.0.0.0 through 10.0.9.0 and 11.0.0.0 through 11.0.1.0
could allow an unauthenticated user to execute arbitrary commands with lower user privileges on the system due to improper validation of user supplied input.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://www.ibm.com/support/pages/node/7247215 |
|
History
Mon, 06 Oct 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 06 Oct 2025 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IBM Security Verify Access and IBM Security Verify Access Docker 10.0.0.0 through 10.0.9.0 and 11.0.0.0 through 11.0.1.0 could allow an unauthenticated user to execute arbitrary commands with lower user privileges on the system due to improper validation of user supplied input. | |
| Title | IBM Security Verify Access command execution | |
| First Time appeared |
Ibm
Ibm security Verify Access Ibm security Verify Access Docker |
|
| Weaknesses | CWE-78 | |
| CPEs | cpe:2.3:a:ibm:security_verify_access:10.0.0.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:security_verify_access:10.0.9.0:interm_fix2:*:*:*:*:*:* cpe:2.3:a:ibm:security_verify_access:11.0.0.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:security_verify_access:11.0.1.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:security_verify_access_docker:10.0.0.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:security_verify_access_docker:10.0.9.0:interm_fix2:*:*:*:*:*:* cpe:2.3:a:ibm:security_verify_access_docker:11.0.0.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:security_verify_access_docker:11.0.1.0:*:*:*:*:*:*:* |
|
| Vendors & Products |
Ibm
Ibm security Verify Access Ibm security Verify Access Docker |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: ibm
Published: 2025-10-06T16:53:43.179Z
Updated: 2025-10-06T19:58:39.023Z
Reserved: 2025-04-15T21:16:54.209Z
Link: CVE-2025-36354
Updated: 2025-10-06T19:58:35.947Z
Status : Awaiting Analysis
Published: 2025-10-06T17:16:05.127
Modified: 2025-10-08T19:38:32.610
Link: CVE-2025-36354
No data.