Description
IBM Security Verify Directory (Container) 10.0.0 through 10.0.0.3 IBM Security Verify Directory could be vulnerable to malicious file upload by not validating file type. A privileged user could upload malicious files into the system that can be sent to victims for performing further attacks against the system.
Published: 2026-04-22
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Malicious File Upload
Action: Apply Patch
AI Analysis

Impact

IBM Security Verify Directory (Container) versions 10.0.0 through 10.0.0.3 allow a privileged user to upload files without validating the file type. By uploading arbitrary files, an attacker can place malicious payloads on the system that may later be sent to other users, potentially enabling phishing or remote code execution on victim machines.

Affected Systems

The vulnerability affects IBM Security Verify Directory (Container) releases 10.0.0, 10.0.0.1, 10.0.0.2, and 10.0.0.3.

Risk and Exploitability

The CVSS score of 5.5 indicates a moderate severity, while the EPSS score of less than 1% suggests a low likelihood of exploitation at this time. The flaw is not listed in the CISA KEV catalog. Exploitation requires a privileged user or local/remote access to the container and the ability to upload a file that the system will later deliver to victims. The risk is increased if the system automatically distributes or executes uploaded files, but the narrow scope and low EPSS score mitigate immediate widespread impact.

Generated by OpenCVE AI on April 29, 2026 at 02:21 UTC.

Remediation

Vendor Solution

IBM strongly encourages customers to update their systems promptly. Product(s)Affected Version(s)FixIBM Security Verify Directory (Container)10.0.0-10.0.3 https://www.ibm.com/support/pages/ibm-security-verify-directory-version-10040-download-document


OpenCVE Recommended Actions

  • Download and install the latest IBM Security Verify Directory (Container) update from the IBM support page (e.g., version 10.0.4) as described in the official advisory.
  • Configure the application to reject all non‑whitelisted file types during upload by enforcing strict MIME type checks.
  • Restrict file uploads to authenticated privileged users only, disabling any anonymous or generic upload endpoints.

Generated by OpenCVE AI on April 29, 2026 at 02:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 13 May 2026 23:15:00 +0000

Type Values Removed Values Added
First Time appeared Ibm security Verify Directory
CPEs cpe:2.3:a:ibm:security_verify_directory:*:*:*:*:*:*:*:*
Vendors & Products Ibm security Verify Directory

Thu, 23 Apr 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Apr 2026 00:00:00 +0000

Type Values Removed Values Added
Description IBM Security Verify Directory (Container) 10.0.0 through 10.0.0.3 IBM Security Verify Directory could be vulnerable to malicious file upload by not validating file type. A privileged user could upload malicious files into the system that can be sent to victims for performing further attacks against the system.
Title Security vulnerability has been detected in IBM Security Verify Directory
First Time appeared Ibm
Ibm security Verify Directory Container
Weaknesses CWE-434
CPEs cpe:2.3:a:ibm:security_verify_directory_container:10.0.0.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:security_verify_directory_container:10.0.0:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm security Verify Directory Container
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:L'}


Subscriptions

Ibm Security Verify Directory Security Verify Directory Container
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-04-23T14:35:26.541Z

Reserved: 2025-04-15T21:16:13.121Z

Link: CVE-2025-36074

cve-icon Vulnrichment

Updated: 2026-04-23T14:35:21.448Z

cve-icon NVD

Status : Analyzed

Published: 2026-04-23T00:16:43.093

Modified: 2026-05-13T23:08:37.987

Link: CVE-2025-36074

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-29T02:30:07Z

Weaknesses