📧 info@ciso.sa | 📱 +966550939344 | Riyadh, Kingdom of Saudi Arabia
🔧 Scheduled Maintenance — Saturday 2:00-4:00 AM AST. Some features may be temporarily unavailable.    ●   
💎
Pro Plan 50% Off Unlock all AI features, unlimited reports, and priority support. Upgrade
Search Center
ESC to close
Global vulnerability Information Technology and Infrastructure HIGH 44m Global data_breach Education HIGH 58m Global data_breach Education HIGH 2h Global vulnerability Information Technology CRITICAL 2h Global supply_chain Software Development and Technology HIGH 3h Global vulnerability Information Technology and Telecommunications CRITICAL 3h Global apt Financial Services, Banking HIGH 9h Global vulnerability Technology and Software Development HIGH 12h Global vulnerability Government and Federal Agencies CRITICAL 12h Global supply_chain Software Development and Open-Source Ecosystems HIGH 13h Global vulnerability Information Technology and Infrastructure HIGH 44m Global data_breach Education HIGH 58m Global data_breach Education HIGH 2h Global vulnerability Information Technology CRITICAL 2h Global supply_chain Software Development and Technology HIGH 3h Global vulnerability Information Technology and Telecommunications CRITICAL 3h Global apt Financial Services, Banking HIGH 9h Global vulnerability Technology and Software Development HIGH 12h Global vulnerability Government and Federal Agencies CRITICAL 12h Global supply_chain Software Development and Open-Source Ecosystems HIGH 13h Global vulnerability Information Technology and Infrastructure HIGH 44m Global data_breach Education HIGH 58m Global data_breach Education HIGH 2h Global vulnerability Information Technology CRITICAL 2h Global supply_chain Software Development and Technology HIGH 3h Global vulnerability Information Technology and Telecommunications CRITICAL 3h Global apt Financial Services, Banking HIGH 9h Global vulnerability Technology and Software Development HIGH 12h Global vulnerability Government and Federal Agencies CRITICAL 12h Global supply_chain Software Development and Open-Source Ecosystems HIGH 13h
Vulnerabilities

CVE-2025-36074

Medium
CWE-434 — Weakness Type
Published: Apr 23, 2026  ·  Modified: Apr 25, 2026  ·  Source: NVD
CVSS v3
5.5
🔗 NVD Official
📄 Description (English)

IBM Security Verify Directory (Container) 10.0.0 through 10.0.0.3 IBM Security Verify Directory could be vulnerable to malicious file upload by not validating file type. A privileged user could upload malicious files into the system that can be sent to victims for performing further attacks against the system.

🤖 AI Executive Summary

IBM Security Verify Directory (Container) versions 10.0.0 through 10.0.0.3 contain a file upload validation vulnerability (CWE-434) that allows privileged users to upload malicious files without proper type validation. While requiring elevated privileges, this could enable attackers to distribute malicious content to victims for secondary attacks. No patch is currently available, requiring immediate compensating controls.

📄 Description (Arabic)

🤖 AI Intelligence Analysis Analyzed: May 25, 2026 16:16
🇸🇦 Saudi Arabia Impact Assessment
Saudi organizations using IBM Security Verify Directory for identity and access management—particularly in banking (SAMA-regulated institutions), government agencies (NCA oversight), healthcare systems, and telecommunications (STC, Mobily)—face insider threat risks. Compromised directory systems could enable credential theft, unauthorized access propagation, and supply chain attacks targeting downstream users. The impact is elevated in sectors managing critical infrastructure and sensitive citizen data.
🏢 Affected Saudi Sectors
Banking & Financial Services (SAMA-regulated) Government & Public Administration (NCA oversight) Healthcare & Medical Services Energy & Utilities (ARAMCO, national grid) Telecommunications (STC, Mobily, Zain) Critical Infrastructure Large Enterprise IT Services
⚖️ Saudi Risk Score (AI)
6.2
/ 10.0
🔧 Remediation Steps (English)
Immediate Actions:
1. Inventory all IBM Security Verify Directory deployments (versions 10.0.0-10.0.0.3) across your organization
2. Restrict file upload functionality to essential administrative users only; implement role-based access controls (RBAC) limiting upload permissions
3. Disable container-based deployments if possible; migrate to patched versions when available
4. Implement file type whitelisting at the application and network levels (block executable, script, and archive file uploads)
5. Deploy file integrity monitoring (FIM) on upload directories to detect unauthorized modifications
6. Enable comprehensive audit logging for all file upload activities with user identification and timestamps
7. Scan existing uploaded files for malicious signatures using updated antivirus/EDR tools
8. Implement network segmentation to isolate the directory service from end-user systems
9. Monitor for CVE-2025-36074 patch releases from IBM and apply immediately upon availability
10. Conduct insider threat assessment focusing on privileged user activities and file access patterns
🔧 خطوات المعالجة (العربية)
الإجراءات الفورية:
1. قم بحصر جميع نشرات IBM Security Verify Directory (الإصدارات 10.0.0-10.0.0.3) عبر مؤسستك
2. قيد وظيفة تحميل الملفات على المستخدمين الإداريين الأساسيين فقط؛ طبق ضوابط الوصول القائمة على الأدوار (RBAC) لتحديد صلاحيات التحميل
3. عطّل النشرات المستندة إلى الحاويات إن أمكن؛ انتقل إلى الإصدارات المصححة عند توفرها
4. طبق قائمة بيضاء لنوع الملف على مستويات التطبيق والشبكة (احجب تحميل الملفات القابلة للتنفيذ والنصوص والأرشيفات)
5. نشّر مراقبة سلامة الملفات (FIM) على دلائل التحميل للكشف عن التعديلات غير المصرح بها
6. فعّل تسجيل التدقيق الشامل لجميع أنشطة تحميل الملفات مع تحديد المستخدم والطوابع الزمنية
7. امسح الملفات المحملة الموجودة بحثاً عن التوقيعات الضارة باستخدام أدوات مكافحة الفيروسات/EDR المحدثة
8. طبق تقسيم الشبكة لعزل خدمة الدليل عن أنظمة المستخدمين النهائيين
9. راقب إصدارات تصحيح CVE-2025-36074 من IBM وطبقها فوراً عند توفرها
10. أجرِ تقييم تهديد المستخدمين الداخليين مع التركيز على أنشطة المستخدمين ذوي الصلاحيات وأنماط الوصول إلى الملفات
📋 Regulatory Compliance Mapping
🟢 NCA ECC 2024
ECC 2024 A.5.1.1 - Access Control Policies (privileged user restrictions) ECC 2024 A.5.2.1 - User Registration and Access Rights Management ECC 2024 A.5.3.1 - Management of Privileged Access Rights ECC 2024 A.8.2.1 - Classification of Information (file type validation) ECC 2024 A.12.2.1 - Change Management (patch deployment tracking) ECC 2024 A.12.4.1 - Event Logging (audit trail requirements)
🔵 SAMA CSF
Governance & Risk Management - Insider Threat Controls Information Security - Access Control & Authentication Information Security - Data Protection & File Integrity Operational Resilience - Incident Detection & Response Compliance & Audit - Logging & Monitoring Requirements
🟡 ISO 27001:2022
A.5.1.1 - Policies for the use of information and other associated assets A.5.2.1 - Information security responsibilities A.5.3.1 - Segregation of duties A.6.2.1 - Competence assessment A.8.1.1 - Inventory of assets A.8.2.1 - Classification of information A.8.3.1 - Handling of assets A.12.2.1 - Change management A.12.4.1 - Event logging A.12.4.3 - Protection of log information
🟣 PCI DSS v4.0.1
Requirement 1.1 - Firewall configuration standards (network segmentation) Requirement 2.2.4 - Configure system security parameters Requirement 6.2 - Ensure security patches are installed Requirement 7.1 - Limit access to system components Requirement 10.2 - Implement automated audit trails
📊 CVSS Score
5.5
/ 10.0 — Medium
📊 CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:L
Attack VectorN — None / Network
Attack ComplexityL — Low / Local
Privileges RequiredH — High
User InteractionN — None / Network
ScopeU — Unchanged
ConfidentialityN — None / Network
IntegrityH — High
AvailabilityL — Low / Local
📋 Quick Facts
Severity Medium
CVSS Score5.5
CWECWE-434
EPSS0.05%
Exploit No
Patch ✗ No
Published 2026-04-23
Source Feed nvd
🇸🇦 Saudi Risk Score
6.2
/ 10.0 — Saudi Risk
Priority: HIGH
🏷️ Tags
CWE-434
Share this CVE
📣 Found this valuable?
Share it with your cybersecurity network
in LinkedIn 𝕏 X / Twitter 💬 WhatsApp ✈ Telegram
🍪 Privacy Preferences
CISO Consulting — Compliant with Saudi Personal Data Protection Law (PDPL)
We use cookies and similar technologies to provide the best experience on our platform. You can choose which types you accept.
🔒
Essential Always On
Required for the website to function properly. Cannot be disabled.
📋 Sessions, CSRF tokens, authentication, language preferences
📊
Analytics
Help us understand how visitors use the site and improve performance.
📋 Page views, session duration, traffic sources, performance metrics
⚙️
Functional
Enable enhanced features like content personalization and preferences.
📋 Dark/light theme, font size, custom dashboards, saved filters
📣
Marketing
Used to deliver content and ads relevant to your interests.
📋 Campaign tracking, retargeting, social media analytics
Privacy Policy →
CISO AI Assistant
Ask anything · Documents · Support
🔐

Introduce Yourself

Enter your details to access the full assistant

Your info is private and never shared
💬
CyberAssist
Online · responds in seconds
5 / 5
🔐 Verify Your Identity

Enter your email to receive a verification code before submitting a support request.

Enter to send · / for commands 0 / 2000
CISO AI · Powered by Anthropic Claude
✦ Quick Survey Help Us Improve CISO Consulting Your feedback shapes the future of our platform — takes less than 2 minutes.
⚠ Please answer this question to continue

How would you rate your overall experience with our platform?

Rate from 1 (poor) to 5 (excellent)

🎉
Thank you!
Your response has been recorded.