Impact
An inconsistency in how a reverse proxy interprets HTTP requests allows a remote attacker to obtain sensitive information. Based on the description, it is inferred that the vulnerability does not require authentication; malicious requests can be crafted to subvert normal request parsing, leading to inadvertent exposure of protected data.
Affected Systems
The vulnerability applies to IBM Verify Identity Access and IBM Verify Identity Access Container versions 11.0 through 11.0.3, and to IBM Security Verify Access and IBM Security Verify Access Container versions 10.0 through 10.0.9.2. All listed configurations are impacted until the supplied fix versions are installed.
Risk and Exploitability
The CVSS score of 8.1 categorizes this as a high‑impact flaw; however, the EPSS score is not available, so the current likelihood of exploitation is unknown. The vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be remote via the reverse proxy, requiring network access to the proxy and the ability to construct specially crafted HTTP requests. If exploited, the attacker could read or manipulate sensitive data controlled by the affected applications.
OpenCVE Enrichment