VYPR
High severity8.5NVD Advisory· Published Oct 6, 2025· Updated Jun 17, 2026

CVE-2025-36355

CVE-2025-36355

Description

IBM Security Verify Access and IBM Security Verify Access Docker 10.0.0.0 through 10.0.9.0 and 11.0.0.0 through 11.0.1.0

could allow a locally authenticated user to execute malicious scripts from outside of its control sphere.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

15
  • cpe:2.3:a:ibm:security_verify_access:*:*:*:*:*:*:*:*+ 5 more
    • cpe:2.3:a:ibm:security_verify_access:*:*:*:*:*:*:*:*range: >=10.0.0.0,<10.0.9.0
    • cpe:2.3:a:ibm:security_verify_access:10.0.0.0:*:*:*:*:*:*:*range: 10.0.0.0
    • cpe:2.3:a:ibm:security_verify_access:10.0.9.0:-:*:*:*:*:*:*
    • cpe:2.3:a:ibm:security_verify_access:10.0.9.0:interim_fix1:*:*:*:*:*:*
    • cpe:2.3:a:ibm:security_verify_access:10.0.9.0:interim_fix2:*:*:*:*:*:*
    • (no CPE)range: 10.0.0.0 - 10.0.9.0, 11.0.0.0 - 11.0.1.0
  • cpe:2.3:a:ibm:security_verify_access_docker:*:*:*:*:*:*:*:*+ 3 more
    • cpe:2.3:a:ibm:security_verify_access_docker:*:*:*:*:*:*:*:*range: >=10.0.0.0,<10.0.9.0
    • cpe:2.3:a:ibm:security_verify_access_docker:10.0.9.0:-:*:*:*:*:*:*
    • cpe:2.3:a:ibm:security_verify_access_docker:10.0.9.0:interim_fix1:*:*:*:*:*:*
    • cpe:2.3:a:ibm:security_verify_access_docker:10.0.9.0:interim_fix2:*:*:*:*:*:*
  • cpe:2.3:a:ibm:verify_identity_access:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:ibm:verify_identity_access:*:*:*:*:*:*:*:*range: >=11.0.0.0,<11.0.1.0
    • cpe:2.3:a:ibm:verify_identity_access:11.0.1.0:-:*:*:*:*:*:*
  • cpe:2.3:a:ibm:verify_identity_access_docker:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:ibm:verify_identity_access_docker:*:*:*:*:*:*:*:*range: >=11.0.0.0,<11.0.1.0
    • cpe:2.3:a:ibm:verify_identity_access_docker:11.0.1.0:-:*:*:*:*:*:*
  • Range: 10.0.0.0 - 10.0.9.0, 11.0.0.0 - 11.0.1.0

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.