Impact
The vulnerability is a cross‑site scripting flaw (CWE‑79) affecting IBM Verify Identity Access, IBM Verify Identity Access Container, IBM Security Verify Access, and IBM Security Verify Access Container products. The CVE description lists the affected product series but provides no further technical detail. The primary impact is the potential delivery of malicious scripts to users interacting with the affected components.
Affected Systems
Affected products are IBM Verify Identity Access versions 11.0.0 through 11.0.3 (including the interim fix 001), IBM Verify Identity Access Container versions 11.0.0 through 11.0.3, IBM Security Verify Access versions 10.0.0 through 10.0.9.2 (including the interim fix 001), and IBM Security Verify Access Container versions 10.0.0 through 10.0.9.2.
Risk and Exploitability
The CVSS score is 6.1, indicating moderate severity. The EPSS score is less than 1%, implying a low likelihood of exploitation. The vulnerability is not listed in CISA KEV, so no publicly known exploits exist. Because the CVE description does not provide details on the exploitation path or conditions, the exact attack vector remains unspecified.
OpenCVE Enrichment