Impact
A remote attacker can trigger a denial of service in IBM Verify Identity Access and IBM Security Verify Access by sending requests containing resource references that are not properly validated. The flaw causes the application to consume excessive resources or abort normal processing, interrupting service for legitimate users. This indicates that insufficient validation or checking of input can lead to a denial of services.
Affected Systems
The issue affects IBM Verify Identity Access and IBM Verify Identity Access Container for all releases up through version 11.0.2 and earlier, with the interim patch 11.0.3 IF2 addressing the flaw. IBM Security Verify Access and its Container are affected for all releases prior to version 10.0.9.2, with the interim patch 10.0.9.2 IF2 providing the fix. The affected CPEs correspond to security_verify_access 10.x and 11.x, and their respective container variants.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity vulnerability, while the EPSS score of <1% reflects a very low probability of exploitation in the wild. The flaw is not listed in the CISA KEV catalog. The attack vector is remote, requiring only network access to the Verify Access services; no local privileges are needed. Successful exploitation would result in service disruption for all users of the affected applications.
OpenCVE Enrichment