logo

Critical Flaw CVE-2025-36356 (CVSS 9.3) in IBM Security Verify Access Allows Root Privilege Escalation

ID: ce1abcc5-ea70-5155-b815-6f35049df957

STIX ID: report--ce1abcc5-ea70-5155-b815-6f35049df957

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2025-10-07

Date Updated: 2026-04-22

Author: Ddos

...
...

IBM released patches for three vulnerabilities in IBM Security Verify Access and IBM Verify Identity Access: CVE-2025-36355 (client-side/script injection, CVSS 8.5), CVE-2025-36356 (local privilege escalation to root, CVSS 9.3 - critical), and CVE-2025-36354 (unauthenticated arbitrary command execution, CVSS 7.3). The flaws affect Docker and appliance deployments (listed 10.0.x–11.0.x versions); fixes are available in Fix Packs 10.0.9.0-IF3 and 11.0.1.0-IF1 and should be applied immediately to mitigate potential privilege escalation and command execution risks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.