CVE-2025-36087

HIGH

IBM Security Verify Access < 10.0.9 - Hard-coded Credentials

Title source: rule
STIX 2.1

Description

IBM Security Verify Access 10.0.0 through 10.0.9, 11.0.0, IBM Verify Identity Access Container 10.0.0 through 10.0.9, and 11.0.0, under certain configurations, contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data.

Scores

CVSS v3 8.1
EPSS 0.0002
EPSS Percentile 6.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-798
Status published
Products (2)
ibm/security_verify_access 10.0.0 - 10.0.9
ibm/verify_identity_access 11.0.0
Published Oct 13, 2025
Tracked Since Feb 18, 2026