Impact
The vulnerability is a denial of service flaw in the reverse proxy component of IBM Verify Identity Access and IBM Security Verify Access. When certain configurations are present, an attacker can trigger the reverse proxy to become unresponsive, causing the affected services to fail.
Affected Systems
Affected systems include IBM Verify Identity Access versions 11.0 through 11.0.3 and IBM Verify Identity Access Container versions 11.0 through 11.0.3; IBM Security Verify Access versions 10.0 through 10.0.9.2 and IBM Security Verify Access Container versions 10.0 through 10.0.9.2. The releases listed above are explicitly identified by IBM as vulnerable.
Risk and Exploitability
The CVSS score of 3.1 indicates low severity and low exploitability. The EPSS score is not available. IBM has not listed this vulnerability in the CISA KEV catalog. The vulnerability can be triggered by sending crafted requests to the reverse proxy in affected configurations, potentially causing a service crash or reset.
OpenCVE Enrichment