Impact
IBM Security Verify Access’s reverse proxy accepts HTTP requests and forwards them to external third‑party services. A flaw in the proxy’s handling of request parameters permits an attacker to inject arbitrary parameters into the forwarded request. The injected parameters can alter how the external service processes the request, potentially exposing sensitive data or allowing unintended code execution if the external service is vulnerable to the injected input.
Affected Systems
The affected products are IBM Security Verify Access version 10.0.9.2 and IBM Verify Identity Access version 11.0.3, including their containerized deployments. All instances running older versions of these products are vulnerable.
Risk and Exploitability
The CVSS score of 6.5 and the EPSS score of < 1% indicate a moderate risk but a very low exploitation probability. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector involves network traffic routed to the reverse proxy; an attacker must craft HTTP requests that reach the proxy and are forwarded to a third‑party service. Successful exploitation would allow the to inject or modify parameters in the forwarded request, potentially exposing data or enabling downstream code execution depending on how the target service processes the injected parameters.
OpenCVE Enrichment