Impact
A path traversal weakness in IBM Security Verify Access 10.0‑10.0.9.2 and IBM Verify Identity Access 11.0‑11.0.3 enables a remote attacker to write arbitrary files. The flaw resides in input validation for file paths (CWE‑22), allowing overwriting or creating files outside the intended directory. Successful exploitation could corrupt configuration files, replace executables, or write malicious payloads, potentially leading to system compromise or denial service.
Affected Systems
The vulnerability affects IBM Security Verify Access appliances running versions 10.0 through 10.0.9.2 and container images up to 10.0.9.2, as well as IBM Verify Identity Access appliances running versions 11.0 through 11.0.3 and container images up to 11.0.3. All impacted wrappers, including the classic and containerised deployments, must be assessed for the update requirement.
Risk and Exploitability
With a CVSS score of 7.5 the flaw is considered high impact. The EPSS score is not available, so the current exploit probability cannot be quantified, but the vulnerability is not listed in the CISA KEV catalogue, suggesting no confirmed widespread exploitation yet. Based on the description, the likely attack vector is remote, through the management or authentication interfaces exposed to the network. An attacker must be able to authenticate or send crafted requests to the vulnerable service to trigger the path traversal.
OpenCVE Enrichment