Impact
The vulnerability is a format string injection in the management interface of IBM Verify Identity Access and IBM Security Verify Access systems. By submitting a malicious HTTP request that exploits the unvalidated format string, an attacker can cause the application to crash or expose sensitive data stored in memory. This weakness is classified as CWE‑134.
Affected Systems
Affected products include IBM Verify Identity Access versions 11.0 through 11.0.3 and the corresponding Verify Identity Access Container edition, as well as IBM Security Verify Access versions 10.0.0 through 10.0.9.2 and its Security Verify Access Container edition. The latest patches—Verify Identity Access 11.0.3 IF1 and Security Verify Access 10.0.9.2 IF2—provide remediation for these versions.
Risk and Exploitability
The CVSS score of 8.7 highlights high severity. While the EPSS score is currently unavailable, the vulnerability is documented and not listed in CISA KEV, indicating that exploitation is possible but not confirmed in the wild. The likely attack vector involves an attacker crafting a specialized HTTP request to the vulnerable management interface, which may be reachable from the network. Successful exploitation would lead to system downtime and potentially disclose confidential information.
OpenCVE Enrichment