Impact
IBM Security Verify Directory (Container) versions 10.0.0 through 10.0.0.3 allow a privileged user to upload files without validating the file type. By uploading arbitrary files, an attacker can place malicious payloads on the system that may later be sent to other users, potentially enabling phishing or remote code execution on victim machines.
Affected Systems
The vulnerability affects IBM Security Verify Directory (Container) releases 10.0.0, 10.0.0.1, 10.0.0.2, and 10.0.0.3.
Risk and Exploitability
The CVSS score of 5.5 indicates a moderate severity, while the EPSS score of less than 1% suggests a low likelihood of exploitation at this time. The flaw is not listed in the CISA KEV catalog. Exploitation requires a privileged user or local/remote access to the container and the ability to upload a file that the system will later deliver to victims. The risk is increased if the system automatically distributes or executes uploaded files, but the narrow scope and low EPSS score mitigate immediate widespread impact.
OpenCVE Enrichment