Impact
In certain configurations, the local management interface of IBM Verify Identity Access and IBM Security Verify Access is vulnerable to cross‑site scripting. An authenticated user can embed arbitrary JavaScript into the web UI, potentially altering intended functionality and exposing credentials that are stored in the trusted session. The weakness corresponds to input validation and output encoding failure (CWE‑79).
Affected Systems
IBM Verify Identity Access versions 11.0.0 through 11.0.3 and IBM Security Verify Access versions 10.0.0 through 10.0.9.2 are affected. The vendor recommends upgrading to IBM Verify Identity Access v11.0.3.1 and IBM Security Verify Access v10.0.9.3 to mitigate the flaw.
Risk and Exploitability
The CVSS score of 4.9 classifies the issue as medium severity. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a legitimately authenticated local user exploiting the management interface; therefore, the risk is limited to environments where privileged users have access to the interface. Mitigating the flaw reduces the possibility of session credentials being exfiltrated via injected scripts.
OpenCVE Enrichment