Impact
The vulnerability in IBM Verify Identity Access and IBM Security Verify Access allows an attacker to cause a denial of service by exploiting a control flow flaw that can lead to an application crash or resource exhaustion. The weakness is classified under CWE‑835, indicating an infinite loop or recursion that can consume resources until the system becomes unresponsive.
Affected Systems
Affected products include IBM Verify Identity Access versions 11.0 through 11.0.3 and IBM Verify Identity Access Container with the same range. IBM Security Verify Access versions 10.0.0 through 10.0.9.2 are also impacted. Updated patches are available for both the application and its container deployment, with download links provided by IBM.
Risk and Exploitability
The CVSS score of 5.3 denotes a medium‑to‑low severity. The EPSS score is not available, so the exploitation likelihood cannot be precisely quantified, and the vulnerability is not listed in CISA's KEV catalog, suggesting limited public exploitation. The description does not specify whether the vector is remote or local; therefore, the exact attack vector is uncertain but the flaw can be triggered through normal operation of the affected services. No elevated privileges are required beyond typical usage.
OpenCVE Enrichment