Impact
The vulnerability permits an authenticated user to obtain the privileges of another user by sending a specially crafted request. This results in unauthorized elevation of access within the IBM Verify Identity Access or IBM Security Verify Access systems, potentially exposing sensitive data or allowing further attacks. The weakness is identified as CWE‑302, an improper authentication flaw that can lead to privilege escalation.
Affected Systems
Affected products include IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3, as well as IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Security Verify Access Container 10.0 through 10.0.9.2. All listed versions are vulnerable until upgraded to the latest patch releases (11.0.3 IF1 and 10.0.9.2 IF2).
Risk and Exploitability
The CVSS score of 8.1 denotes a high severity vulnerability. Although no EPSS score is available, the absence of a KEV listing suggests exploitation may not yet be widespread, yet the need for an authenticated session lowers the barrier for attackers who already have valid credentials. The risk is therefore significant for environments that host privileged users; an exploit could compromise the entire identity platform if unpatched.
OpenCVE Enrichment