Description
IBM Security Verify Identity Access Reverse Proxy in certain configurations may provide weaker than expected cryptographic validation of user supplied data.
Published: 2026-09-15
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: Cryptographic Validation Failure
Action: Patch Now
AI Analysis

Impact

IBM Security Verify Identity Access Reverse Proxy sometimes uses weaker cryptographic checks on user supplied data, which can allow attackers to tamper with payloads without detection. The vulnerability is a flaw in the cryptographic validation process, classified as CWE-327. An attacker who can influence the data sent through the reverse proxy may be able to bypass authentication or modify requests, potentially leading to unauthorized access or data disclosure.

Affected Systems

Affected products include IBM Verify Identity Access and IBM Security Verify Access, in both standard and container editions. The vulnerable releases are IBM Verify Identity Access 11.0.0–11.0.3 (interim fix 001) and IBM Security Verify Access 10.0.0–10.0.9.2 (interim fix 001). Containers run the same version ranges and require the corresponding container interim fixes.

Risk and Exploitability

The CVSS score of 7.5 indicates medium‑high severity. No EPSS score is available, and the vulnerability is not listed in CISA KEV. The likely attack vector is remote, through network traffic that reaches the reverse proxy. Given the cryptographic weakness, exploitation could result in significant confidentiality and integrity impacts if an attacker can craft tampered requests successfully.

Generated by OpenCVE AI on September 15, 2026 at 22:27 UTC.

Remediation

Vendor Solution

IBM encourages customers to update their systems promptly. Appliance Affected Products Fix availability IBM Verify Identity Access Download IBM Verify Identity Access v11.0.3 IF2 https://www.ibm.com/support/fixcentral/quickorder IBM Security Verify Access Download IBM Security Verify Access v10.0.9.2 IF2 https://www.ibm.com/support/fixcentral/quickorder Container Container Download https://docs.verify.ibm.com/ibm-security-verify-access/docs/containers


OpenCVE Recommended Actions

  • Upgrade IBM Verify Identity Access to v11.0.3 IF2 from the IBM Fix Central link.
  • Upgrade IBM Security Verify Access to v10.0.9.2 IF2 from the IBM Fix Central link.
  • Apply the container interim fix for both Identity Access Container and Security Verify Access Container as described in the IBM Container documentation.

Generated by OpenCVE AI on September 15, 2026 at 22:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-327
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description IBM Security Verify Identity Access Reverse Proxy in certain configurations may provide weaker than expected cryptographic validation of user supplied data.
Title Security vulnerabilities have been addressed in IBM Verify Identity Access and IBM Security Verify Access
First Time appeared Ibm
Ibm security Verify Access
Ibm security Verify Access Container
Ibm verify Identity Access
Ibm verify Identity Access Container
CPEs cpe:2.3:a:ibm:security_verify_access:10.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:security_verify_access:10.0.9.2:interim_fix_001:*:*:*:*:*:*
cpe:2.3:a:ibm:security_verify_access_container:10.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:security_verify_access_container:10.0.9.2:interim_fix_001:*:*:*:*:*:*
cpe:2.3:a:ibm:verify_identity_access:11.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:verify_identity_access:11.0.3:interim_fix_001:*:*:*:*:*:*
cpe:2.3:a:ibm:verify_identity_access_container:11.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:verify_identity_access_container:11.0.3:interim_fix_001:*:*:*:*:*:*
Vendors & Products Ibm
Ibm security Verify Access
Ibm security Verify Access Container
Ibm verify Identity Access
Ibm verify Identity Access Container
References

Subscriptions

Ibm Security Verify Access Security Verify Access Container Verify Identity Access Verify Identity Access Container
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-15T19:33:26.743Z

Reserved: 2026-06-10T18:39:35.410Z

Link: CVE-2026-11929

cve-icon Vulnrichment

Updated: 2026-09-15T19:33:05.053Z

cve-icon NVD

Status : Received

Published: 2026-09-15T18:17:13.283

Modified: 2026-09-15T20:17:03.813

Link: CVE-2026-11929

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T22:30:15Z

Weaknesses
  • CWE-327

    Use of a Broken or Risky Cryptographic Algorithm