Impact
IBM Verify Identity Access contains a CWE-285: Improper Privilege Management flaw that results from improper validation of user-supplied input, allowing an authenticated administrator to execute additional commands they are not entitled to. The vulnerability arises because the input is not properly checked, enabling administrators to run unintended commands.
Affected Systems
The flaw affects IBM Verify Identity Access 11.0.3 Interim Fix 001 and IBM Security Verify Access 10.0.9.2 Interim Fix 001, as well as the corresponding container images IBM Verify Identity Access Container v11.0.3 and IBM Security Verify Access Container v10.0.9.2.
Risk and Exploitability
Based on the description, an attacker who has administrative credentials can supply crafted input to trigger unintended command execution. The CVSS score of 7.2 and an EPSS of <1% indicate a low probability of exploitation, and the vulnerability is not listed in CISA KEV. This flaw enables privilege escalation within the affected system.
OpenCVE Enrichment