CVE-2025-36087
8.1IBM · Security Verify Access and Verify Identity Access Container
IBM Security Verify Access and Verify Identity Access Container contain hard-coded credentials used for authentication, external communication, or internal data encryption.
Executive summary
IBM Security Verify Access products are vulnerable to hard-coded credential flaws, potentially allowing unauthorized access or encryption compromise.
Vulnerability
This vulnerability involves the use of hard-coded credentials within the application, which may be utilized for inbound authentication, communication with external components, or internal data encryption. The flaw is exploitable by an unauthenticated attacker, although the attack complexity is rated as high.
Business impact
The presence of hard-coded credentials represents a significant security risk, as it may allow unauthorized actors to bypass authentication mechanisms or decrypt sensitive internal data. With a CVSS score of 8.1, the potential for total impact on confidentiality, integrity, and availability necessitates immediate attention to prevent unauthorized system access or data exposure.
Remediation
Immediate Action: Administrators must update to the corrected versions, specifically applying IBM Security Verify Access v10.0.9 IF2 or upgrading to IBM Verify Identity Access v11.0.1.
Proactive Monitoring: Monitor authentication logs for suspicious activity or unauthorized access attempts that deviate from established user behavior patterns.
Compensating Controls: Ensure that affected instances are restricted to isolated, secure network segments and verify that robust network perimeter defenses are in place to limit potential exposure to untrusted traffic.
Exploitation status
Public Exploit Available: No (exploit_available unknown).
Analyst recommendation
Given the high CVSS severity and the nature of hard-coded credential flaws, organizations must prioritize the application of the vendor-supplied patches. Failure to remediate could result in a complete compromise of the security appliance and any data it protects, making immediate updates essential to maintaining an effective security posture.