Impact
The vulnerability enables an attacker who already has read‑only access to elevate their permissions and modify or deploy configurations outside of their designated scope. This represents a classic privilege‑escalation scenario that undermines the integrity of system configuration and deployment settings. The weakness corresponds to insecure permission handling (CWE-863).
Affected Systems
IBM Verify Identity Access versions 11.0 through 11.0.2, IBM Security Verify Access versions 10.0 through 10.0.9.1, IBM Verify Identity Access Container 11.0 through 11.0.2, and IBM Security Verify Access Container 10.0 through 10.0.9.1 are affected. These include the standard IBM products for identity verification and access management, both in standalone and containerized form.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, while the EPSS score of less than 1% suggests a very low probability of exploitation in the immediate future. It is not listed in CISA KEV. Based on the description, it is inferred that an attacker must already possess read‑only access; from that position they can exploit the permission handling flaw to carry out unauthorized configuration changes or deployments. The potential impact includes compromised integrity of deployed services and potential availability disruption.
OpenCVE Enrichment