Impact
IBM Verify Access and Verify Identity Access have a heap-based out-of-bounds read that can be triggered by a specially crafted request from a remote attacker. The flaw permits a limited memory read and can ultimately crash or stall the target process, leading to a denial of service. This weakness is classified as Improper Memory Access (CWE‑125).
Affected Systems
Affected versions include IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3. Container deployments of these product lines are also impacted and require the updated container images supplied by IBM.
Risk and Exploitability
The CVSS score is 3.7, indicating moderate severity. No EPSS score is published, suggesting limited current exploitation evidence. The vulnerability is not listed in CISA KEV. The attack vector is remote; a crafted request sent to the vulnerable service can trigger the out-of-bounds read and cause a denial of service.
OpenCVE Enrichment