CVE-2025-36355: IBM Security Verify Access code execution
IBM Security Verify Access and IBM Security Verify Access Docker 10.0.0.0 through 10.0.9.0 and 11.0.0.0 through 11.0.1.0
could allow a locally authenticated user to execute malicious scripts from outside of its control sphere.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2025-36355?
CVE-2025-36355 is considered a high-severity vulnerability due to the potential for local users to execute malicious scripts.
How do I fix CVE-2025-36355?
To mitigate CVE-2025-36355, update IBM Security Verify Access or IBM Security Verify Access Docker to the latest versions 10.0.9.1 or 11.0.1.1 or later.
Who is affected by CVE-2025-36355?
CVE-2025-36355 affects users of IBM Security Verify Access and IBM Security Verify Access Docker versions from 10.0.0.0 to 10.0.9.0 and 11.0.0.0 to 11.0.1.0.
What types of attacks can be executed using CVE-2025-36355?
CVE-2025-36355 could allow an attacker to execute unauthorized commands or scripts, increasing the risk of system compromise.
Is there a workaround for CVE-2025-36355?
Currently, there is no specific workaround for CVE-2025-36355 other than upgrading to a patched version of the software.