IBM Security Verify Access Appliance and Docker 10.0 through 10.0.8 could allow a remote attacker to enumerate usernames due to an observable response discrepancy of disabled accounts.
2025-06-11T15:15:29.177
2025-08-13T14:31:41.243
Analyzed
CVSSv3.1: 5.3 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | ibm | security_verify_access | < 10.0.9 | Yes |
Application | ibm | security_verify_access_docker | < 10.0.9 | Yes |