Impact
An input validation flaw in IBM Verify Identity Access and IBM Security Verify Access allows an administrator to execute commands beyond their intended privileges, effectively enabling privilege escalation and compromising the integrity of the system. The flaw permits the injection of arbitrary commands through improperly validated user-supplied input, which can lead to unauthorized data access, modification, or disruption. The impact reaches the administrative boundary, giving attackers elevated access that could be leveraged for broader compromise of the infrastructure.
Affected Systems
Affected products include IBM Verify Identity Access version 11.0 through 11.0.3 and its containerized variant 11.0 through 11.0.3. IBM Security Verify Access versions 10.0 through 10.0.9.2 and the corresponding container versions 10.0.0 through 10.0.9.2 are also impacted. These versions are specified for the base product and container deployments under the IBM Security Verify Access and IBM Verify Identity Access lines.
Risk and Exploitability
The CVSS score of 7.2 indicates a high severity, and while the EPSS score is not available, the vulnerability may be exploitable by an authenticated administrator. The flaw has not been listed in the CISA KEV catalog, suggesting no publicly known exploits yet, but the potential for privilege escalation remains significant. Attackers would need to supply crafted input to an authenticated administrative interface; no remote unauthenticated access is required. The risk is moderate to high depending on the exposure of privileged administrative interfaces.
OpenCVE Enrichment