Back

CRITICAL

IBM Security Verify Access hard coded credentials

Published Oct 13, 2025

Description

IBM Security Verify Access 10.0.0 through 10.0.9, 11.0.0, IBM Verify Identity Access Container 10.0.0 through 10.0.9, and 11.0.0, under certain configurations, contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data.

Affected products

Remediation

Vendor solution

IBM Security Verify Access 10.0.0 - 10.0.9

Download IBM Security Verify Access v10.0.9 IF2 https://www.ibm.com/support/fixcentral/swg/downloadFixes

IBM Verify Identity Access 11.0

Download IBM Verify Identity Access v11.0.1 https://www.ibm.com/support/pages/download-ibm-verify-identity-access-v1101

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner ibm
Published Oct 13, 2025
Updated Oct 15, 2025
Reserved Apr 15, 2025
CISA Vulnrichment
Updated Oct 15, 2025
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner ibm
Published Oct 13, 2025
Updated Oct 15, 2025
Exploited since n/a
EUVD-2025-33916