Impact
IBM Security Verify Access versions 10.0 to 10.0.9.2 and IBM Verify Identity Access versions 11.0 to 11.0.3 are vulnerable to audit log forgery, which allows an attacker to inject or alter audit entries. This flaw undermines the integrity of security logs, potentially masking malicious activity or enabling the attacker to impersonate legitimate users. The weakness is a classic example of improper neutralization of log entries (CWE-88).
Affected Systems
The vulnerable products are IBM Verify Identity Access and IBM Security Verify Access, including their containerated forms. Affected appliance versions span 10.0.0 through 10.0.9.2 for Security Verify Access and 11.0.0 through 11.0.3 for Verify Identity Access. Corresponding container images with the same major versions are also impacted.
Risk and Exploitability
With a CVSS score of 2.7 the risk is classified as low, and the EPSS score is not available. The flaw is not listed in the CISA KEV catalog, indicating no known active exploitation at the time of this analysis. Exploitation likely requires authenticated access to the system’s logging mechanisms, as forging audit logs normally requires privileges to write to log files or system endpoints. Based on the description, the attack vector is inferred to be remote via the exposed logging interface, with the threat mainly to the integrity of audit evidence rather than direct system compromise.
OpenCVE Enrichment