Recommended Free Tools
Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
Security researcher Pierre Barre disclosed a group of vulnerabilities in IBM Security Verify Access (ISVA), an enterprise platform that handles authentication, federation, authorization and network-access policy. The reported weaknesses included an authentication bypass, seven reported remote-code-execution flaws, eight privilege-escalation issues, information disclosure, insecure downloads, hardcoded cryptographic keys and unsafe defaults.
The “36 vulnerabilities” figure needs context. Public reporting describes a principal disclosure of about 32 issues plus four separately reported ISVA vulnerabilities. IBM issued several advisories covering subsets of the findings; there was no single CVE, severity rating or patch that represented all 36. Some issues were addressed in ISVA 10.0.7 and 10.0.8, while a later IBM bulletin lists versions through 10.0.8 as affected for another group and identifies 10.0.9 as the fix.
Nothing in the available reporting confirms that these flaws were exploited in the wild or that IBM customers suffered a breach. They nevertheless affected the identity plane, so administrators should treat exposed or unpatched ISVA systems as high-priority security issues.
What IBM Security Verify Access does
ISVA is an enterprise identity and access-management product. Organizations use it to authenticate users, enforce authorization policies, provide federation and single sign-on, administer multifactor authentication, and control access to applications and network resources. Deployments can run as an IBM appliance, as Docker/container workloads, or in a mixed architecture.
#1 Best Overall
The runtime container is particularly important: it performs backend authentication and federation functions. A compromise there could affect the applications and users that rely on ISVA, even if the management interface is not exposed to the internet. ISVA should not automatically be treated as identical to IBM Verify Identity Access; some IBM advisories cover both product families, but administrators must match each notice to their exact product and deployment.
SecurityWeek’s account of Barre’s research says the vulnerabilities were discovered in October 2022, reported to IBM in early 2023 and publicly discussed on November 5, 2024. The report describes potential attack paths, not a confirmed customer incident.
SecurityWeek’s disclosure report is the primary public account of the researcher’s findings.
Why the count is reported as 36
The headline number combines related reporting rather than a single IBM vulnerability list. SecurityWeek’s URL and portions of its story refer to 32 vulnerabilities, while the broader discussion includes four additional ISVA issues disclosed separately. IBM’s public advisories cover only a subset of the researcher’s findings.
Therefore, “36” should be read as 36 vulnerabilities discussed by the researcher and reporting, not 36 CVEs or 36 identical remote exploits. Categories can overlap: one defect may contribute to both information disclosure and privilege escalation, for example.
| Reported class | Potential consequence | Typical condition |
|---|---|---|
| Authentication bypass | Backend access without normal authentication | Network reachability and a particular request behavior |
| Remote code execution | Arbitrary code execution in the affected service | Depends on the individual flaw and exposed interface |
| Privilege escalation | Execution or administration as root | Often local access or a vulnerable optional service |
| Hardcoded or exposed keys | Decryption of configuration data | Access to an affected image or configuration file |
| Insecure snapshot retrieval | Malicious snapshot substitution or interception | Man-in-the-middle position or inadequate certificate validation |
| Weak defaults | Root, SSH or cluster-account exposure | Specific service or configuration state |
| Outdated components | Exposure to known third-party flaws | Affected package and reachable attack surface |
The reported set also included denial-of-service, database-compromise and supply-chain or package-repository concerns. Not every issue was remotely exploitable, and the public material does not provide a complete authoritative vulnerability-by-vulnerability matrix.
The most serious described attack path
Barre told SecurityWeek that an attacker who could reach the ISVA runtime backend could abuse an authentication-bypass behavior by sending a specific HTTP header. The attacker could then interact with the backend as an arbitrary user and, in the described scenario, enroll a malicious multifactor authenticator on an administrative account.
Do these 3 things before closing this tab:
1Scan for outdated or missing drivers - takes under a minute2Repair Windows errors before they cause bigger problems3Fix the driver behind crashes, sound loss and screen glitches- Reach the runtime service from an internal network, trusted host or other position with access to the backend.
- Trigger the reported authentication-bypass behavior.
- Operate as a selected user or administrator.
- Remove legitimate authenticators or register an attacker-controlled authenticator.
- Maintain access, lock out administrators or alter identity configuration.
- Use the compromised identity infrastructure to reach downstream applications and users.
This is a researcher-described attack scenario, not evidence that every deployment could be compromised in exactly this way. It does show why an “internal-only” identity service still deserves internet-grade controls. SecurityWeek also reported that a low-privileged user on a trusted machine might be able to reach the backend even when external access was blocked.
What data and privileges could be exposed?
The research reported hardcoded encryption and decryption keys in some official IBM Docker images and keys that were world-readable by default. Those keys could reportedly decrypt a file containing ISVA configuration, including credentials, RSA keys and certificates. That creates consequences beyond the original software bug: stolen credentials or private keys can remain useful after a software upgrade.
Other reported weaknesses included local privilege escalation to root, command injection, arbitrary-code execution and escape from the telnet client. SecurityWeek also cited outdated OpenSSL packages, possible root login when an SSH server was installed, an undefined password for the cluster account, snapshot downloads over HTTPS without proper certificate validation, and a third-party repository configuration that could create supply-chain risk.
Rank #3
These findings have different prerequisites. Some require local access, a trusted-network position, an optional service or an insecure configuration. They should not be presented as 36 internet-remote vulnerabilities.
IBM’s patch and advisory timeline
- October 2022: Barre discovered the issues.
- Early 2023: The issues were reported to IBM, according to SecurityWeek’s account.
- June 25, 2024: IBM published a bulletin fixing a group of issues in ISVA 10.0.8.0, including CVE-2023-38371 and CVE-2024-35137.
- November 5, 2024: SecurityWeek published its broader account of the disclosure.
- February 3, 2025: A later IBM bulletin listed ISVA 10.0.0 through 10.0.8 as affected for another group and identified ISVA 10.0.9 as the remediation release.
For the June 2024 bulletin, IBM lists Docker releases 10.0.0.0 through 10.0.7.1 and appliance releases 10.0.0.0 through 10.0.7.0 as affected. The specified appliance fix is 10.0.8-ISS-ISVA-FP0000, with a corresponding updated container image. IBM’s bulletin also identifies CVE-2023-38371 as a weaker-than-expected cryptographic-algorithm issue (CVSS 5.9) and CVE-2024-35137 as local privilege escalation involving exposed sensitive configuration information.
In a separate advisory, IBM describes CVE-2024-28787 as information disclosure or denial of service through a specially crafted HTTP request, with a CVSS base score of 8.7, affecting ISVA appliance and container versions 10.0.0 through 10.0.7.
Read the original notices: IBM’s 10.0.8 bulletin, the CVE-2024-28787 bulletin, and the later bulletin naming 10.0.9.
Do not assume that 10.0.8 fixes every issue discussed in the 36 count. Fixes were distributed across releases and advisories. IBM’s affected-product tables generally describe supported versions; an old, unsupported release omitted from a table is not thereby proven safe.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Rank #4
Administrator response checklist
1. Identify exposure
- Inventory every ISVA appliance, container, image tag and fix-pack level.
- Determine whether runtime, management, SSH or telnet interfaces are reachable from the internet, user networks or general-purpose workstations.
- Map the deployment to each applicable IBM advisory; appliance fixes and container-image updates are not interchangeable.
2. Contain while changes are planned
- Remove unnecessary internet exposure and restrict runtime access to required hosts and management networks.
- Review firewall, load-balancer and security-group rules.
- Disable optional SSH or telnet services when they are not required.
- Check the
clusteraccount and any default or undefined password state. - Review custom repository configuration and ensure snapshot downloads validate the remote certificate.
- Preserve relevant logs before restarting or replacing systems.
Segmentation is a compensating control, not a substitute for patching. It does not repair hardcoded keys, weak local permissions, outdated libraries or unsafe administrative logic.
3. Apply the correct IBM fix
Use the fix pack or image tag specified for your supported release. IBM’s June 2024 container guidance uses:
docker pull icr.io/isva/verify-access:[tag]
Replace [tag] with the supported fixed tag confirmed in IBM’s current distribution and support documentation. Do not blindly deploy an unverified latest tag. For issues whose affected range includes 10.0.8, review the later advisory and the 10.0.9 remediation rather than stopping at 10.0.8.
4. Rotate secrets after remediation
Assess and, where exposure is plausible, rotate ISVA administrator and service-account passwords, RSA private keys, TLS certificates and keys, federation-signing keys, database credentials, MFA recovery material, and credentials stored in exported or snapshot configuration files. Coordinate federation-key and certificate changes with relying parties so that rotation does not unintentionally break authentication.
Free tools Windows power users keep installed
One-click scans. No signup required.
5. Check for compromise
Review logs for unusual runtime-backend requests or authentication headers; new MFA authenticators on privileged accounts; deleted authenticators; administrator lockouts; unexpected exports or snapshots; root, SSH or telnet activity; unapproved repository downloads; and changes to federation, certificate or signing-key configuration.
Best Value
A patched system is not necessarily a clean system. If keys or credentials may have been exposed, run software remediation and incident response as separate workstreams.
What is known—and what is not
- Known: Barre reported a broad set of ISVA weaknesses spanning authentication, code execution, privilege, secrets and configuration.
- Conditional: Exploitability depended on network reachability, deployment type, optional services and configuration.
- Not established: The reviewed sources do not confirm exploitation in the wild or a breach of IBM customers.
- Not universal: No single CVSS score, CVE or 10.0.8 update represents all 36 reported issues.
For current fix availability and support status, consult IBM’s product support portal and the advisory that matches your exact appliance or container release.
Frequently Asked Questions
Does “36 vulnerabilities” mean 36 CVEs?
No. The number combines a principal disclosure of about 32 issues with four separately reported ISVA vulnerabilities. IBM advisories cover subsets, and the public material does not establish a one-to-one mapping to 36 CVEs.
Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minutePC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Is ISVA 10.0.8 a complete fix?
Not for every reported issue. IBM fixed specific groups in 10.0.8.0, while a later bulletin lists versions through 10.0.8 as affected for another set and identifies 10.0.9 as the fix.
Was there a confirmed IBM customer breach?
The reviewed reporting describes potential compromise scenarios, but does not establish exploitation in the wild or a confirmed customer breach.
The Bottom Line
Treat IBM Security Verify Access as a critical identity-plane asset. Inventory both appliances and containers, apply the IBM advisory-specific fix, restrict runtime access, rotate potentially exposed credentials and keys, and investigate MFA, configuration and backend-access logs. Network isolation alone is not equivalent to remediation.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

