Back

MEDIUM

IBM Security Verify Access information disclosure

Published Jun 11, 2025

Description

IBM Security Verify Access Appliance and Docker 10.0 through 10.0.8 could allow a remote attacker to enumerate usernames due to an observable response discrepancy of disabled accounts.

Affected products

Remediation

Vendor solution

IBM encourages customers to update their systems promptly.

Passport Advantage IBM Security Verify Access 10.0.9: https://www.ibm.com/support/pages/node/7177661 IBM Verify Identity Access 11.0: https://www.ibm.com/support/pages/node/7167873

Fix Central Product Name Fixed in VRMF

Fix availability IBM Security Verify Access 10.0.9 10.0.9-ISS-ISVA-FP0000 IBM Verify Identity Access 11.0 11.0.0-ISS-IVIA-FP0000

Docker Log into IBM Cloud Registry and then execute the corresponding commands as the following: https://www.ibm.com/support/pages/node/7167873#container

Weaknesses (1)

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner ibm
Published Jun 11, 2025
Updated Aug 24, 2025
Reserved Dec 31, 2024
CISA Vulnrichment
Updated Jun 11, 2025
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner ibm
Published Jun 11, 2025
Updated Aug 24, 2025
Exploited since n/a
EUVD-2025-18121