CVE-2025-36354: IBM Security Verify Access command execution
IBM Security Verify Access and IBM Security Verify Access Docker 10.0.0.0 through 10.0.9.0 and 11.0.0.0 through 11.0.1.0
could allow an unauthenticated user to execute arbitrary commands with lower user privileges on the system due to improper validation of user supplied input.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2025-36354?
CVE-2025-36354 is considered a critical vulnerability due to its potential to allow unauthenticated users to execute arbitrary commands.
How do I fix CVE-2025-36354?
To remediate CVE-2025-36354, update IBM Security Verify Access or IBM Security Verify Access Docker to versions 10.0.9.0 or 11.0.1.0 or later.
What systems are affected by CVE-2025-36354?
CVE-2025-36354 affects IBM Security Verify Access and IBM Security Verify Access Docker versions ranging from 10.0.0.0 to 10.0.9.0 and 11.0.0.0 to 11.0.1.0.
Can CVE-2025-36354 be exploited remotely?
Yes, CVE-2025-36354 can be exploited by remote attackers since it allows unauthenticated users to execute commands.
What consequences can arise from CVE-2025-36354?
Exploitation of CVE-2025-36354 can lead to unauthorized access and control over the affected system, compromising its security.