CVE-2025-36074

MEDIUM

Security vulnerability has been detected in IBM Security Verify Directory

Title source: cna
STIX 2.1

Description

IBM Security Verify Directory (Container) 10.0.0 through 10.0.0.3 IBM Security Verify Directory could be vulnerable to malicious file upload by not validating file type. A privileged user could upload malicious files into the system that can be sent to victims for performing further attacks against the system.

Scores

CVSS v3 5.5
EPSS 0.0005
EPSS Percentile 14.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-434
Status published
Products (1)
IBM/Security Verify Directory (Container) 10.0.0 - 10.0.0.3
Published Apr 23, 2026
Tracked Since Apr 23, 2026