Impact
IBM Verify Identity users to a crafted URL appearing to be from a legitimate site. By persuading a victim to visit this URL, the attacker can spoof the displayed site and redirect the victim to a malicious web location that looks trusted, enabling phishing attacks or the theft of highly sensitive information. The flaw is specifically a CWE‑601 type vulnerability involving improper handling of redirect URLs.
Affected Systems
The affected products are IBM Verify Identity Access and IBM Security Verify Access, including the Container variants. The patches that address this vulnerability are IBM Verify Identity Access v11.0.3 IF2 and IBM Security Verify Access v10.0.9.2 IF2. Container images should be updated following IBM’s container documentation link.
Risk and Exploitability
The EPSS score is < 1% and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is through the public web interfaces of the affected products, where an attacker can supply a malicious redirect target. Because the flaw enables phishing that could lead to credential compromise or further attacks, the risk remains significant for environments that expose these services to untrusted users.
OpenCVE Enrichment