{"dataType":"CVE_RECORD","dataVersion":"5.1","cveMetadata":{"cveId":"CVE-2025-36354","assignerOrgId":"9a959283-ebb5-44b6-b705-dcc2bbced522","state":"PUBLISHED","assignerShortName":"ibm","dateReserved":"2025-04-15T21:16:54.209Z","datePublished":"2025-10-06T16:53:43.179Z","dateUpdated":"2025-10-06T19:58:39.023Z"},"containers":{"cna":{"affected":[{"cpes":["cpe:2.3:a:ibm:security_verify_access:10.0.0.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:security_verify_access:10.0.9.0:interm_fix2:*:*:*:*:*:*","cpe:2.3:a:ibm:security_verify_access:11.0.0.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:security_verify_access:11.0.1.0:*:*:*:*:*:*:*"],"defaultStatus":"unaffected","product":"Security Verify Access Appliance","vendor":"IBM","versions":[{"lessThanOrEqual":"10.0.9.0 IF2","status":"affected","version":"10.0.0.0","versionType":"semver"},{"lessThanOrEqual":"11.0.1.0","status":"affected","version":"11.0.0.0","versionType":"semver"}]},{"cpes":["cpe:2.3:a:ibm:security_verify_access_docker:10.0.0.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:security_verify_access_docker:10.0.9.0:interm_fix2:*:*:*:*:*:*","cpe:2.3:a:ibm:security_verify_access_docker:11.0.0.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:security_verify_access_docker:11.0.1.0:*:*:*:*:*:*:*"],"defaultStatus":"unaffected","product":"Security Verify Access Docker","vendor":"IBM","versions":[{"lessThanOrEqual":"10.0.9.0 IF2","status":"affected","version":"10.0.0.0","versionType":"semver"},{"lessThanOrEqual":"11.0.1.0","status":"affected","version":"11.0.0.0","versionType":"semver"}]}],"descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"IBM Security Verify Access and IBM Security Verify Access Docker 10.0.0.0 through 10.0.9.0 and 11.0.0.0 through 11.0.1.0 \n\n<span style=\"background-color: rgb(255, 255, 255);\">\n\n<span style=\"background-color: rgb(255, 255, 255);\">could allow an unauthenticated user to execute arbitrary commands with lower user privileges on the system due to improper validation of user supplied input.</span>\n\n</span>"}],"value":"IBM Security Verify Access and IBM Security Verify Access Docker 10.0.0.0 through 10.0.9.0 and 11.0.0.0 through 11.0.1.0 \n\n\n\ncould allow an unauthenticated user to execute arbitrary commands with lower user privileges on the system due to improper validation of user supplied input."}],"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"LOW","baseScore":7.3,"baseSeverity":"HIGH","confidentialityImpact":"LOW","integrityImpact":"LOW","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","version":"3.1"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-78","description":"CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')","lang":"en","type":"CWE"}]}],"providerMetadata":{"orgId":"9a959283-ebb5-44b6-b705-dcc2bbced522","shortName":"ibm","dateUpdated":"2025-10-06T16:53:43.179Z"},"references":[{"tags":["vendor-advisory","patch"],"url":"https://www.ibm.com/support/pages/node/7247215"}],"source":{"discovery":"UNKNOWN"},"title":"IBM Security Verify Access command execution","x_generator":{"engine":"Vulnogram 0.2.0"}},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2025-10-06T19:58:30.805460Z","id":"CVE-2025-36354","options":[{"Exploitation":"none"},{"Automatable":"yes"},{"Technical Impact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2025-10-06T19:58:39.023Z"}}]}}