IBM Security Verify Access hard coded credentials
Published Oct 13, 2025
9.8
CRITICALCVSS 3.1
EPSS 0.29%
Description
IBM Security Verify Access 10.0.0 through 10.0.9, 11.0.0, IBM Verify Identity Access Container 10.0.0 through 10.0.9, and 11.0.0, under certain configurations, contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data.
Affected products
-
- Version 10.0.0StatusaffectedConstraints<=10.0.9
- Version 11.0.0StatusaffectedConstraints-
- Version
-
- Version 10.0.0StatusaffectedConstraints<=10.0.9
- Version 11.0.0StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| IBM | Security Verify Access | unaffected |
| |||||||||
| IBM | Verify Identity Access Container | unaffected |
|
- ≥ 10.0.0 · ≤ 10.0.9
- 11.0.0
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
IBM Security Verify Access 10.0.0 - 10.0.9
Download IBM Security Verify Access v10.0.9 IF2 https://www.ibm.com/support/fixcentral/swg/downloadFixes
IBM Verify Identity Access 11.0
Download IBM Verify Identity Access v11.0.1 https://www.ibm.com/support/pages/download-ibm-verify-identity-access-v1101
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-33916 Advisory
- https://www.ibm.com/support/pages/node/7247753 vendor-advisorypatchVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-33916 | Advisory | |
| https://www.ibm.com/support/pages/node/7247753 | vendor-advisorypatchVendor Advisory |
Change history (0)
No recorded changes yet.