Impact
Reverse proxy configurations in IBM Verify Identity Access and IBM Security Verify Access may perform weaker than expected cryptographic validation of user supplied data. This weakness could allow an attacker to tamper with or forge data that is then accepted by downstream components, potentially leading to integrity or authorization bypass. The vulnerability is a weakness relating to cryptographic mechanisms.
Affected Systems
IBM Security Verify Access versions 10.0.0 through 10.0.9.2 and their container editions, and IBM Verify Identity Access versions 11.0.0 through 11.0.3 and their container editions are affected. The applicable fixes are the 10.0.9.2 IF2 release for Security Verify Access and the 11.0.3 IF1 release for Verify Identity Access.
Risk and Exploitability
The CVSS score of 6.8 indicates a medium severity risk. EPSS is not available, so no current exploitation probability is reported, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote, via the reverse proxy over a network, as inferred from the description. Formal exploit evidence is not documented in the provided data.
OpenCVE Enrichment