CVE-2025-36354

IBM Security Verify Access and IBM Security Verify Access Docker 10.0.0.0 through 10.0.9.0 and 11.0.0.0 through 11.0.1.0 



could allow an unauthenticated user to execute arbitrary commands with lower user privileges on the system due to improper validation of user supplied input.
OS Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.3 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
ibmCNA
7.3 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 28%
VendorProductVersion
ibmsecurity_verify_access
10.0.0.0 ≤
𝑥
< 10.0.9.0
ibmsecurity_verify_access
10.0.9.0
ibmsecurity_verify_access
10.0.9.0:interim_fix1
ibmsecurity_verify_access
10.0.9.0:interim_fix2
ibmsecurity_verify_access_docker
10.0.0.0 ≤
𝑥
< 10.0.9.0
ibmsecurity_verify_access_docker
10.0.9.0
ibmsecurity_verify_access_docker
10.0.9.0:interim_fix1
ibmsecurity_verify_access_docker
10.0.9.0:interim_fix2
ibmverify_identity_access
11.0.0.0 ≤
𝑥
< 11.0.1.0
ibmverify_identity_access
11.0.1.0
ibmverify_identity_access_docker
11.0.0.0 ≤
𝑥
< 11.0.1.0
ibmverify_identity_access_docker
11.0.1.0
𝑥
= Vulnerable software versions