Impact
The vulnerability is caused by improper neutralization of command arguments in IBM Security Verify Access and IBM Verify Identity Access. This flaw enables a remote authenticated attacker to execute arbitrary system commands. Based on the description, it is inferred that such execution could compromise confidentiality, integrity, and availability by potentially installing malware, exfiltrating data, or disrupting services. The weakness is classified as CWE‑88 and represents a classic command injection that requires successful authentication before exploitation.
Affected Systems
Affected products are IBM Security Verify Access versions 10.0 through 10.0.9.2 and IBM Verify Identity Access versions 11.0 through 11.0.3, including corresponding container deployments. Any deployment running these versions without the fixes is vulnerable.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity vulnerability, and although EPSS data is not available, the absence of a KEV listing does not reduce the potential for exploitation. The attack vector is remote authenticated, meaning an attacker who can gain valid user credentials may launch the exploit with user privileges. Based on the description, it is inferred that the risk is significant for organizations that rely on these IBM Identity Access solutions, especially if default or weak credentials are used. Immediate remediation is recommended.
OpenCVE Enrichment