IBM Security Verify Access information disclosure
Published Jun 11, 2025
5.3
MEDIUMCVSS 3.1
EPSS 0.34%
Description
IBM Security Verify Access Appliance and Docker 10.0 through 10.0.8 could allow a remote attacker to enumerate usernames due to an observable response discrepancy of disabled accounts.
Affected products
-
- Version 10.0StatusaffectedConstraints<=10.0.8
- Version
-
- Version 10.0StatusaffectedConstraints<=10.0.8
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| IBM | Security Verify Access | unaffected |
| ||||||
| IBM | Security Verify Access Docker | unaffected |
|
- ≥ 10.0.0 · < 10.0.9
- ≥ 10.0.0 · < 10.0.9
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
IBM encourages customers to update their systems promptly.
Passport Advantage IBM Security Verify Access 10.0.9: https://www.ibm.com/support/pages/node/7177661 IBM Verify Identity Access 11.0: https://www.ibm.com/support/pages/node/7167873
Fix Central Product Name Fixed in VRMF
Fix availability IBM Security Verify Access 10.0.9 10.0.9-ISS-ISVA-FP0000 IBM Verify Identity Access 11.0 11.0.0-ISS-IVIA-FP0000
Docker Log into IBM Cloud Registry and then execute the corresponding commands as the following: https://www.ibm.com/support/pages/node/7167873#container
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-18121 Advisory
- https://www.ibm.com/support/pages/node/7236314 vendor-advisorypatchVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-18121 | Advisory | |
| https://www.ibm.com/support/pages/node/7236314 | vendor-advisorypatchVendor Advisory |
Change history (0)
No recorded changes yet.