Impact
IBM Verify Identity Access lacks proper origin validation, allowing a remote attacker to carry out actions on behalf of the victim and potentially launch further attacks. This flaw permits the execution of privileged operations through crafted requests that bypass normal authentication checks, constituting a remote impersonation vulnerability.
Affected Systems
IBM Verify Identity Access (version 11.0.3 interim fix) and IBM Security Verify Access (version 10.0.9.2 interim fix) are affected, as well as their corresponding container editions. The advisory references interim fixes for the base products and their container variants, which are available for download as of the advisory release.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity. EPSS score is < 1%, and the vulnerability is not listed in CISA's KEV catalog, suggesting no publicly known exploits at this time. The attack vector is inferred to be remote, likely via HTTP requests wherein the origin header is not validated. While exploitation would require the attacker to send specifically crafted requests, the potential for privilege escalation remains significant if the flaw is leveraged.
OpenCVE Enrichment