CVE-2025-36087

8.1

IBM · Security Verify Access and Verify Identity Access Container

IBM Security Verify Access and Verify Identity Access Container contain hard-coded credentials used for authentication, external communication, or internal data encryption.

Executive summary

IBM Security Verify Access products are vulnerable to hard-coded credential flaws, potentially allowing unauthorized access or encryption compromise.

Vulnerability

This vulnerability involves the use of hard-coded credentials within the application, which may be utilized for inbound authentication, communication with external components, or internal data encryption. The flaw is exploitable by an unauthenticated attacker, although the attack complexity is rated as high.

Business impact

The presence of hard-coded credentials represents a significant security risk, as it may allow unauthorized actors to bypass authentication mechanisms or decrypt sensitive internal data. With a CVSS score of 8.1, the potential for total impact on confidentiality, integrity, and availability necessitates immediate attention to prevent unauthorized system access or data exposure.

Remediation

Immediate Action: Administrators must update to the corrected versions, specifically applying IBM Security Verify Access v10.0.9 IF2 or upgrading to IBM Verify Identity Access v11.0.1.

Proactive Monitoring: Monitor authentication logs for suspicious activity or unauthorized access attempts that deviate from established user behavior patterns.

Compensating Controls: Ensure that affected instances are restricted to isolated, secure network segments and verify that robust network perimeter defenses are in place to limit potential exposure to untrusted traffic.

Exploitation status

Public Exploit Available: No (exploit_available unknown).

Analyst recommendation

Given the high CVSS severity and the nature of hard-coded credential flaws, organizations must prioritize the application of the vendor-supplied patches. Failure to remediate could result in a complete compromise of the security appliance and any data it protects, making immediate updates essential to maintaining an effective security posture.

More IBM CVEs

Sources