Impact
IBM Verify Identity Access contains an improper validation flaw that allows an administrator to execute additional commands they are not entitled to. The vulnerability arises because user‑supplied input is not properly checked, giving an authenticated admin the ability to run arbitrary commands. This can lead to unauthorized changes to configuration, unauthorized data access, and disruption of services.
Affected Systems
The flaw affects IBM Verify Identity Access v11.0.3 Interim Fix 001 and IBM Security Verify Access v10.0.9.2 Interim Fix 001. The corresponding container images – IBM Verify Identity Access Container v11.0.3 and IBM Security Verify Access Container v10.0.9.2 – are also impacted.
Risk and Exploitability
With a CVSS score of 7.2 the vulnerability represents a high‑severity risk. No EPSS score is available and the issue is not listed in CISA KEV, indicating no confirmed exploit data. An attacker must be able to gain access to an administrator account (or supply crafted input via an authenticated interface) to exploit the flaw. Because the attack requires privileged access, the risk is high for environments where administrative interfaces are reachable remotely or locally. Prompt application of the interim fixes mitigates this risk.
OpenCVE Enrichment