CVE-2025-36074 is a file upload validation vulnerability affecting IBM Security Verify Directory (Container) versions 10.0.0 through 10.0.0.3, where the system fails to properly validate uploaded file types. A privileged attacker could exploit this weakness to upload malicious files that could subsequently be distributed to victims for launching follow-on attacks against the environment. The vulnerability carries a CVSS severity rating of 5.5 (Medium) with a network-based attack vector requiring high-level privileges but no user interaction. While the integrity impact is rated as high, the overall risk is moderated by the attack complexity and privilege requirements, resulting in a FAUCET Risk Score of 33.0/100. The low EPSS score of 0.00036 indicates minimal real-world prevalence compared to other known vulnerabilities. There is currently no evidence of active exploitation in the wild. The vulnerability is not listed on the CISA Known Exploited Vulnerabilities catalog and remains on the Inactive Hot List, suggesting limited community attention and no publicly available proof-of-concept code at this time. Organizations running affected versions should prioritize patching, though the requirement for privileged access reduces the immediate threat window.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 10.0.0, <= 10.0.3CPE matchmatch criteria | cpe:2.3:a:ibm:security_verify_directory:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.