Privilege Escalation Vulnerability in IBM Security Verify Access Products
CVE-2025-36356

9.3CRITICAL

What is CVE-2025-36356?

A vulnerability exists in IBM Security Verify Access and its Docker version, which could enable a locally authenticated user to escalate their privileges, gaining unauthorized root access. This flaw results from the application executing with excessive privileges, violating the principle of least privilege and potentially compromising system integrity. It is crucial for users of the affected versions to assess their security posture and implement available patches to mitigate risks.

Affected Version(s)

Security Verify Access Appliance 10.0.0.0 <= 10.0.9.0 IF2

Security Verify Access Appliance 11.0.0.0 <= 11.0.1.0

Security Verify Access Docker 10.0.0.0 <= 10.0.9.0 IF2

References

CVSS V3.1

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-36356 : Privilege Escalation Vulnerability in IBM Security Verify Access Products