Impact
An open redirect flaw in IBM Verify Identity Access and IBM Security Verify Access allows a remote attacker to direct victims to arbitrary URLs by issuing a specially crafted request. Because the redirect is not validated, a user who follows the redirected link may be led to a malicious site that could phish credentials or deliver malware. This vulnerability is defined as CWE-601 and primarily compromises the integrity of user trust, potentially exposing confidential information if the phishing attempt succeeds.
Affected Systems
IBM Verify Identity Access versions 11.0 through 11.0.2 and IBM Verify Identity Access Container versions 11.0 through 11.0.2 are impacted. IBM Security Verify Access versions 10.0 through 10.0.9.1 and IBM Security Verify Access Container versions 10.0 through 10.0.9.1 are also affected.
Risk and Exploitability
The vulnerability carries a CVSS score of 3.1, indicating low severity, and an EPSS score of less than 1%, suggesting a very low current exploitation probability. It is not listed in the CISA KEV catalog. The likely attack vector involves a remote attacker sending an HTTP request to the vulnerable application; the flaw is exploitable over the network, but a victim must still engage with the redirected URL to realize the phishing outcome.
OpenCVE Enrichment