Impact
IBM Verify Identity Access can allow a remote attacker to cause a denial of service when it processes incoming request resources without properly validating them. The flaw enables resource consumption beyond normal limits, potentially exhausting memory or CPU, and interrupting service availability. This weakness is classified as CWE-674, improper resource allocation.
Affected Systems
Affected systems include IBM Verify Identity Access versions 11.0.0 through the interim fix 001 and IBM Security Verify Access versions 10.0.0 through the interim fix 001. Container deployments of both products are also vulnerable until replaced with the updated images documented by IBM.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity issue, while the EPSS score of less than 1 percent suggests a low but non‑zero likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a remote, network‑based risk, where an attacker can send specially crafted requests that exploit the lack of resource validation to drain system resources. Because the flaw is triggered by external input, it does not require local privileges and can be leveraged by any entity that can reach the affected system.
OpenCVE Enrichment