CVE-2025-0163: IBM Security Verify Access information disclosure
IBM Security Verify Access Appliance and Docker 10.0 through 10.0.8 could allow a remote attacker to enumerate usernames due to an observable response discrepancy of disabled accounts.
Other sources
IBM Security Verify Access Appliance could allow a remote attacker to enumerate usernames due to an observable response discrepancy of disabled accounts.
— IBM
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-0163?
CVE-2025-0163 is considered a medium severity vulnerability due to the potential for username enumeration.
How do I fix CVE-2025-0163?
To fix CVE-2025-0163, upgrade your IBM Security Verify Access Appliance or Docker to version 10.0.9 or later.
What versions are affected by CVE-2025-0163?
CVE-2025-0163 affects IBM Security Verify Access and Docker versions 10.0 through 10.0.8.
What can an attacker do with CVE-2025-0163?
An attacker can enumerate usernames due to observable response discrepancies with disabled accounts associated with CVE-2025-0163.
Is CVE-2025-0163 specific to certain products?
Yes, CVE-2025-0163 specifically affects IBM Security Verify Access Appliance and Docker.