Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-36074

23
FAUCET Score

CVE-2025-36074 is a file upload validation vulnerability affecting IBM Security Verify Directory (Container) versions 10.0.0 through 10.0.0.3, where the system fails to properly validate uploaded file types. A privileged attacker could exploit this weakness to upload malicious files that could subsequently be distributed to victims for launching follow-on attacks against the environment. The vulnerability carries a CVSS severity rating of 5.5 (Medium) with a network-based attack vector requiring high-level privileges but no user interaction. While the integrity impact is rated as high, the overall risk is moderated by the attack complexity and privilege requirements, resulting in a FAUCET Risk Score of 33.0/100. The low EPSS score of 0.00036 indicates minimal real-world prevalence compared to other known vulnerabilities. There is currently no evidence of active exploitation in the wild. The vulnerability is not listed on the CISA Known Exploited Vulnerabilities catalog and remains on the Inactive Hot List, suggesting limited community attention and no publicly available proof-of-concept code at this time. Organizations running affected versions should prioritize patching, though the requirement for privileged access reduces the immediate threat window.

Impacted Technologies

VendorProductVersion(s)CPE
>= 10.0.0, <= 10.0.3CPE matchmatch criteria
cpe:2.3:a:ibm:security_verify_directory:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.5MEDIUM

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:L

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
HIGH
Availability Impact
LOW
Exploitability Score
1.2
Impact Score
4.2
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.34%
Probability of exploitation in next 30 days
EPSS Percentile
26.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0034 is in the 5th percentile among its peer group of 5,531 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

ibm.com / support/pages/node/7268907
Vendor Advisory