CVE-2025-36003

HIGH

IBM Security Verify Governance - Error Information Exposure

Title source: rule
STIX 2.1

Description

IBM Security Verify Governance Identity Manager 10.0.2 could allow a remote attacker to obtain sensitive information when detailed technical error messages are returned. This information could be used in further attacks against the system.

Scores

CVSS v3 7.5
EPSS 0.0005
EPSS Percentile 13.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-209
Status published
Products (1)
ibm/security_verify_governance 10.0.2
Published Aug 28, 2025
Tracked Since Feb 18, 2026