IBM Security Verify Directory (Container) 10.0.0 through 10.0.0.3 IBM Security Verify Directory could be vulnerable to malicious file upload by not validating file type. A privileged user could upload malicious files into the system that can be sent to victims for performing further attacks against the system.

Project Subscriptions

Vendors Products
Security Verify Directory Container Subscribe
Advisories

No advisories yet.

Fixes

Solution

IBM strongly encourages customers to update their systems promptly. Product(s)Affected Version(s)FixIBM Security Verify Directory (Container)10.0.0-10.0.3 https://www.ibm.com/support/pages/ibm-security-verify-directory-version-10040-download-document


Workaround

No workaround given by the vendor.

History

Thu, 23 Apr 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Apr 2026 00:00:00 +0000

Type Values Removed Values Added
Description IBM Security Verify Directory (Container) 10.0.0 through 10.0.0.3 IBM Security Verify Directory could be vulnerable to malicious file upload by not validating file type. A privileged user could upload malicious files into the system that can be sent to victims for performing further attacks against the system.
Title Security vulnerability has been detected in IBM Security Verify Directory
First Time appeared Ibm
Ibm security Verify Directory Container
Weaknesses CWE-434
CPEs cpe:2.3:a:ibm:security_verify_directory_container:10.0.0.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:security_verify_directory_container:10.0.0:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm security Verify Directory Container
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:L'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-04-23T14:35:26.541Z

Reserved: 2025-04-15T21:16:13.121Z

Link: CVE-2025-36074

cve-icon Vulnrichment

Updated: 2026-04-23T14:35:21.448Z

cve-icon NVD

Status : Received

Published: 2026-04-23T00:16:43.093

Modified: 2026-04-23T00:16:43.093

Link: CVE-2025-36074

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses