Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2025-36355

CVE-2025-36355: IBM Security Verify Access RCE Flaw

CVE-2025-36355 is a remote code execution vulnerability in IBM Security Verify Access that allows locally authenticated users to execute malicious scripts. This article covers technical details, affected versions, and mitigation.

Published:

CVE-2025-36355 Overview

CVE-2025-36355 affects IBM Security Verify Access and IBM Security Verify Access Docker versions 10.0.0.0 through 10.0.9.0, along with IBM Verify Identity Access versions 11.0.0.0 through 11.0.1.0. The vulnerability allows a locally authenticated user to execute malicious scripts from outside the application's control sphere. The issue is classified under [CWE-829: Inclusion of Functionality from Untrusted Control Sphere]. IBM has published an advisory describing the affected versions and remediation guidance.

Critical Impact

A locally authenticated attacker can execute untrusted scripts within IBM Security Verify Access, leading to confidentiality compromise and changes to system integrity and availability across a scope boundary.

Affected Products

  • IBM Security Verify Access 10.0.0.0 through 10.0.9.0 (including Docker editions)
  • IBM Verify Identity Access 11.0.0.0 through 11.0.1.0 (including Docker editions)
  • Interim Fix 1 and Interim Fix 2 releases for 10.0.9.0

Discovery Timeline

  • 2025-10-06 - CVE-2025-36355 published to the National Vulnerability Database
  • 2026-06-17 - Last updated in NVD database

Technical Details for CVE-2025-36355

Vulnerability Analysis

CVE-2025-36355 results from the inclusion of functionality from an untrusted control sphere within IBM Security Verify Access. The product loads or executes scripts whose origin or integrity is not adequately validated. A locally authenticated user with access to the appliance can leverage this weakness to introduce malicious script content that the platform subsequently runs.

Because the scope changes during exploitation, the impact extends beyond the attacker's original privilege boundary. This makes the vulnerability relevant for environments where Verify Access acts as an authentication gateway for downstream applications and identity federation flows.

Root Cause

The root cause is mapped to [CWE-829]. The product incorporates script functionality from a location the attacker can influence, without validating that the source is trusted. When the script executes, it inherits privileges available to the Verify Access runtime rather than the lower-privileged user that introduced it.

Attack Vector

Exploitation requires local access and prior authentication to the IBM Security Verify Access environment. The attacker does not need user interaction. Once authenticated, the attacker stages malicious script content in a path or repository that the product consumes during normal operation. See the IBM Support advisory for component-specific technical details.

Detection Methods for CVE-2025-36355

Indicators of Compromise

  • Unexpected script files or modified configuration files within Verify Access appliance directories
  • New or unusual local user sessions performing administrative actions on the appliance
  • Outbound network connections originating from Verify Access processes to unfamiliar hosts

Detection Strategies

  • Audit local authentication events on Verify Access appliances and correlate with subsequent configuration or script changes
  • Monitor for script execution by Verify Access service accounts that deviates from baseline behavior
  • Compare deployed appliance file hashes against IBM-published reference values for the installed fix level

Monitoring Recommendations

  • Centralize Verify Access and Verify Identity Access logs into your SIEM and alert on changes to script-handling components
  • Track privileged session activity on the appliance management interface
  • Enable file integrity monitoring on directories used by Verify Access for runtime scripts and policy artifacts

How to Mitigate CVE-2025-36355

Immediate Actions Required

  • Apply the IBM-supplied fix or interim fix for your installed version of Security Verify Access or Verify Identity Access
  • Restrict local and administrative access to Verify Access appliances to a minimal set of trusted operators
  • Review existing local accounts on the appliance and remove any that are not actively required

Patch Information

IBM has published remediation details in the IBM Support advisory for CVE-2025-36355. Administrators should upgrade beyond IBM Security Verify Access 10.0.9.0 (including Interim Fix 1 and Interim Fix 2) and IBM Verify Identity Access 11.0.1.0 to a release that addresses CWE-829 in the affected component. Verify the fix level on both bare-metal and Docker deployments.

Workarounds

  • Limit shell and management console access on Verify Access appliances to dedicated administrators using jump hosts and multi-factor authentication
  • Restrict the appliance's ability to load scripts from network locations or shared mounts where feasible
  • Place Verify Access management interfaces on an isolated administrative network segment until patches are applied

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.