Impact
An input validation flaw in the IBM Verify Identity Access and Security Verify Access management interface allows an attacker who already possesses privileged access to craft malicious HTTP requests that trigger the execution of additional operations. This flaw effectively expands the capabilities of an existing privileged user rather than granting new privileges to an unauthenticated attacker. The vulnerability is classified as CWE-78.
Affected Systems
IBM Verify Identity Access versions 11.0 through 11.0.3, IBM Verify Identity Access Container versions 11.0 through 11.0.3, IBM Security Verify Access versions 10.0.0 through 10.0.9.2, and IBM Security Verify Access Container versions 10.0.0 through 10.0.9.2 are impacted.
Risk and Exploitability
With a CVSS score of 7.2, the vulnerability poses a high severity risk. While the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, the lack of publicly known exploits does not diminish the potential for abuse, especially within organizations that expose the management interface beyond trusted networks. The attack requires an existing authenticated privileged session; an attacker who can obtain such credentials may use specially crafted HTTP requests to invoke additional privileged actions. Consequently, mitigating the risk through timely patching is essential, and organizations should limit exposure of the management interface to trusted network segments if immediate patching cannot occur.
OpenCVE Enrichment