Impact
IBM Security Verify Identity Access Reverse Proxy sometimes uses weaker cryptographic checks on user supplied data, which can allow attackers to tamper with payloads without detection. The vulnerability is a flaw in the cryptographic validation process, classified as CWE-327. An attacker who can influence the data sent through the reverse proxy may be able to bypass authentication or modify requests, potentially leading to unauthorized access or data disclosure.
Affected Systems
Affected products include IBM Verify Identity Access and IBM Security Verify Access, in both standard and container editions. The vulnerable releases are IBM Verify Identity Access 11.0.0–11.0.3 (interim fix 001) and IBM Security Verify Access 10.0.0–10.0.9.2 (interim fix 001). Containers run the same version ranges and require the corresponding container interim fixes.
Risk and Exploitability
The CVSS score of 7.5 indicates medium‑high severity. No EPSS score is available, and the vulnerability is not listed in CISA KEV. The likely attack vector is remote, through network traffic that reaches the reverse proxy. Given the cryptographic weakness, exploitation could result in significant confidentiality and integrity impacts if an attacker can craft tampered requests successfully.
OpenCVE Enrichment