Impact
IBM Verify Identity Access and IBM Security Verify Access versions 11.0 through 11.0.2 and 10.0 through 10.0.9.1, respectively, contain a flaw that allows a remote attacker to receive detailed technical error messages in the browser. These error messages reveal sensitive information, such as configuration details or authentication tokens, that can aid subsequent attacks. The vulnerability is identified as CWE-209, which describes the accidental disclosure of confidential data in logs or error messages.
Affected Systems
IBM Verify Identity Access versions 11.0, 11.0.1, and 11.0.2, as well as the corresponding container images, are affected. IBM Security Verify Access versions 10.0, 10.0.1 through 10.0.9.1 and their container counterparts are also vulnerable. IBM recommends updating to IBM Verify Identity Access v11.0.3 and IBM Security Verify Access v10.0.9.2, which are available for download, and for containers, downloading the latest image from the IBM Verify documentation site.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate impact if exploited. The EPSS score of < 1% indicates a very low but non-zero probability of exploitation. The vulnerability is listed as not part of the CISA KEV catalog. The likely attack vector is remote, requiring an attacker to trigger a detailed technical error that the application outputs to the browser. Once sensitive information is exposed, an attacker may leverage those details to conduct further attacks against the system.
OpenCVE Enrichment