CRITICAL🇵🇱 Wersja polska

CVE-2025-36356

CVSS 9.3v3.1pub. 2025-10-06upd. 2025-12-15

IBM Security Verify Access and IBM Security Verify Access Docker 10.0.0.0 through 10.0.9.0 and 11.0.0.0 through 11.0.1.0 could allow a locally authenticated user to escalate their privileges to root due to execution with more privileges than required.

🤖 AI Analysis
How it works

The vulnerability consists in certain system components being executed with excessive system privileges. A locally logged-in user can exploit this mechanism to gain full root access to the system or container. The bug affects both traditional deployments and containerized environments based on Docker.

Impact

An attacker with local access can obtain full administrative (root) privileges, allowing them to take control of the system, read and modify sensitive data, and destabilize the environment.

Mitigation & patch

Apply patches available from the vendor according to references: https://www.ibm.com/support/pages/node/7247215. As additional remedial measures, restrict local access to the system only to trusted users and apply the principle of least privilege in containerized environments.

Who is affected

IBM Security Verify Access and IBM Security Verify Access Docker in versions 10.0.0.0 – 10.0.9.0 and 11.0.0.0 – 11.0.1.0 (also affects IBM Verify Identity Access and IBM Verify Identity Access Docker variants in the same version ranges).

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
  • IBM Security Verify Access

    APP
    Ibm
    10.0.9.010.0.0.0 – 10.0.9.0 (excl.)
  • IBM Security Verify Access Docker

    APP
    Ibm
    10.0.9.010.0.0.0 – 10.0.9.0 (excl.)
  • IBM Verify Identity Access

    APP
    Ibm
    11.0.1.011.0.0.0 – 11.0.1.0 (excl.)
  • IBM Verify Identity Access Docker

    APP
    Ibm
    11.0.1.011.0.0.0 – 11.0.1.0 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Container
CWE
References

Related vulnerabilities

CVE-2026-1346CRITICAL9.3PL ✓same product

Privilege escalation do root w IBM Security Verify Access i Verify Identity Access

CVE-2024-49806CRITICAL9.4PL ✓same product

IBM Security Verify Access — zakodowane na stałe poświadczenia (hard-coded credentials)

CVE-2024-49805CRITICAL9.4PL ✓same product

IBM Security Verify Access — zakodowane na stałe poświadczenia (hard-coded credentials)

CVE-2024-49803CRITICAL9.8PL ✓same product

IBM Security Verify Access — zdalne wykonanie poleceń (command injection)

CVE-2021-39070CRITICAL9.8PL ✓same product

IBM Security Verify Access — obejście uwierzytelnienia jako dowolny użytkownik