Impact
IBM Verify Identity Access containers accept administrator password change requests but do not apply them correctly; the new password is not enforced, leaving the old password active. This flaw is associated with CWE-522, indicating that authentication credentials are not handled securely and could be reused after an attempted revocation. The vulnerability compromises the integrity of credential management but does not provide a direct path to code execution or privilege escalation.
Affected Systems
Affected products include IBM Verify Identity Access appliance version 11.0.3 IF2 and IBM Security Verify Access appliance version 10.0.9.2 IF2. Container deployments of IBM Verify Identity Access and IBM Security Verify Access are also vulnerable, with interim fix labels 11.0.3 and 10.0.9.2 respectively. All installations running these versions should be considered vulnerable until the official interim fixes are applied.
Risk and Exploitability
The CVSS score is 9.1, but an EPSS score of < 1% is published, and the vulnerability is not listed in CISA KEV, indicating no publicly known exploitation. It is inferred that the attack vector requires administrative access to the system’s management interface or API that processes password changes. An attacker with such access could trigger or observe the flaw and maintain or elevate access using the unchanged credentials. While the risk is moderate due to the low EPSS score, the persistence of unauthorized credentials warrants prompt remediation.
OpenCVE Enrichment