Impact
The CVE involves IBM Verify Identity Access and IBM Security Verify Access products using weaker‑than‑expected cryptographic algorithms, allowing an attacker to decrypt highly sensitive information. This weakness, identified as CWE‑327, compromises data confidentiality and may enable further compromise if the attacker gains access to protected data.
Affected Systems
The affected products are IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1, including their containerized editions for the same version ranges. Customers running any of these versions should verify whether they are at risk and consider upgrading.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, but the EPSS score of less than 1% suggests low likelihood that this vulnerability will be actively exploited in the wild. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, the most likely attack vector would be remote, where an attacker with access to encrypted communications could attempt to decrypt data if the system is using vulnerable algorithms. The vulnerability requires the victim to be running an affected version and that the application is configured to use the weak cryptographic algorithms.
OpenCVE Enrichment