CVE-2025-36087

HIGH

IBM Security Verify Access < 10.0.9 - Hard-coded Credentials

Title source: rule

Description

IBM Security Verify Access 10.0.0 through 10.0.9, 11.0.0, IBM Verify Identity Access Container 10.0.0 through 10.0.9, and 11.0.0, under certain configurations, contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data.

Scores

CVSS v3 8.1
EPSS 0.0002
EPSS Percentile 5.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-798
Status published

Affected Products (2)

ibm/security_verify_access < 10.0.9
ibm/verify_identity_access

Timeline

Published Oct 13, 2025
Tracked Since Feb 18, 2026