Impact
IBM Security Verify Identity Access Reverse Proxy may provide weaker cryptographic validation of user-supplied data than expected when deployed in certain configurations. The vulnerability is a flaw in the cryptographic validation process, classified as CWE-327. An attacker who can influence the data sent through the reverse proxy may be able to bypass authentication or modify requests, potentially leading to unauthorized access or data disclosure.
Affected Systems
Affected products include IBM Verify Identity Access and IBM Security Verify Access, in both standard and container editions. The vulnerable releases are IBM Verify Identity Access 11.0.0–11.0.3 (interim fix 001) and IBM Security Verify Access 10.0.0–10.0.9.2 (interim fix 001); corresponding container interim fixes are also required.
Risk and Exploitability
The CVSS score of 7.5 indicates medium‑high severity. The EPSS score, at the time of analysis, is less than 1%, implying a low probability of exploitation; the vulnerability is not listed in the CISA KEV catalog, so no known active exploitation is publicly reported. Exploitation could occur over the network traffic that reaches the reverse proxy; given the cryptographic weakness, an attacker who successfully crafts tampered requests could potentially bypass authentication or modify requests, leading to unauthorized access or data disclosure.
OpenCVE Enrichment