Impact
The vulnerability is an insufficient validation of incoming request resources in IBM Verify Identity Access and IBM Security Verify Access. An attacker can exploit this flaw to trigger a denial of service, rendering the affected service unavailable. The weakness is identified as CWE-400. The impact is limited to availability, with potential disruption to authentication and access control services.
Affected Systems
IBM Security Verify Access (version 10.0.0 and interim fix 10.0.9.2), IBM Verify Identity Access (version 11.0.0 and interim fix 11.0.3), and the corresponding container images for both products. All affected releases are listed in the provided CPE strings and vendor notes.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity. The EPSS score is <1%, indicating a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is a remote attacker who can send crafted requests to the services, triggering a denial of service. The conditions for exploitation are minimal, requiring only network access to the affected endpoints without authentication.
OpenCVE Enrichment