Impact
The vulnerability in IBM Verify Identity Access originates from improper validation of user‑supplied requests, enabling an authenticated administrator to execute commands beyond their authorized scope. This flaw maps to CWE‑289, allowing the attacker to elevate privileges and potentially modify or exfiltrate system data. The impact includes compromise of confidentiality, integrity, and availability of the affected services.
Affected Systems
Affected products are IBM Verify Identity Access and IBM Security Verify Access, including their containerized variants. Versions lacking the interim fixes Access v11.0.3 IF2 and Security Verify Access v10.0.9.2 IF2—are vulnerable. The package identifiers in the CVE data reference these specific releases.
Risk and Exploitability
The EPSS score is reported as less than 1%, indicating a very low yet non‑zero likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Despite the low exploit probability, the CVSS score of 8.1 indicates high severity because the flaw permits privilege escalation. An attacker who authenticates as an administrator can exploit the flawed request validation to run privileged commands, risking full compromise of affected systems. The attack surface extends across all installations of the cited products without the interim fixes.
OpenCVE Enrichment