Impact
A flaw in IBM Security Verify Access and IBM Verify Identity Access allows a remote authenticated attacker to bypass additional authentication stages in the workflow. An attacker who can obtain valid credentials can exploit this weakness to skip secondary checks, effectively gaining unauthorized access or elevated privileges within the identity management system. The bypass undermines the intended multi‑step authentication process and can lead to data exposure or control over the platform.
Affected Systems
The vulnerability affects IBM Security Verify Access versions 10.0 through 10.0.9.2 and IBM Verify Identity Access versions 11.0 through 11.0.3, including their containerized deployments. The affected products include IBM Security Verify Access, IBM Verify Identity Access, IBM Security Verify Access Container, and IBM Verify Identity Access Container. Administrators should verify if they are running any of these product versions prior to patching.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, and the EPSS score is not available. The vulnerability is not listed in the CISA KEV catalog. Attackers must first obtain valid credentials and have network connectivity to the target, implying a remote authenticated attack vector. Given the absence of a publicly known exploit and the moderate CVSS, the risk remains significant but may not see frequent exploitation until an attacker gains the required credentials.
OpenCVE Enrichment