IBM Security Verify Access Appliance and Docker 10.0 through 10.0.8 could allow a remote attacker to enumerate usernames due to an observable response discrepancy of disabled accounts.
Advisories
Source ID Title
EUVD EUVD EUVD-2025-18121 IBM Security Verify Access Appliance and Docker 10.0 through 10.0.8 could allow a remote attacker to enumerate usernames due to an observable response discrepancy of disabled accounts.
Fixes

Solution

IBM encourages customers to update their systems promptly. Passport Advantage IBM Security Verify Access 10.0.9: https://www.ibm.com/support/pages/node/7177661 IBM Verify Identity Access 11.0: https://www.ibm.com/support/pages/node/7167873 Fix Central Product Name Fixed in VRMF Fix availability IBM Security Verify Access 10.0.9 10.0.9-ISS-ISVA-FP0000 IBM Verify Identity Access 11.0 11.0.0-ISS-IVIA-FP0000 Docker Log into IBM Cloud Registry and then execute the corresponding commands as the following: https://www.ibm.com/support/pages/node/7167873#container


Workaround

No workaround given by the vendor.

History

Wed, 13 Aug 2025 14:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:ibm:security_verify_access:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:security_verify_access_docker:*:*:*:*:*:*:*:*

Sun, 13 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00044}

epss

{'score': 0.00048}


Wed, 11 Jun 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 11 Jun 2025 14:45:00 +0000

Type Values Removed Values Added
Description IBM Security Verify Access Appliance and Docker 10.0 through 10.0.8 could allow a remote attacker to enumerate usernames due to an observable response discrepancy of disabled accounts.
Title IBM Security Verify Access information disclosure
First Time appeared Ibm
Ibm security Verify Access
Ibm security Verify Access Docker
Weaknesses CWE-204
CPEs cpe:2.3:a:ibm:security_verify_access:10.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:security_verify_access:10.0.8:*:*:*:*:*:*:*
cpe:2.3:a:ibm:security_verify_access_docker:10.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:security_verify_access_docker:10.0.8:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm security Verify Access
Ibm security Verify Access Docker
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2025-08-24T11:55:49.924Z

Reserved: 2024-12-31T19:09:14.912Z

Link: CVE-2025-0163

cve-icon Vulnrichment

Updated: 2025-06-11T14:40:45.602Z

cve-icon NVD

Status : Analyzed

Published: 2025-06-11T15:15:29.177

Modified: 2025-08-13T14:31:41.243

Link: CVE-2025-0163

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.