Description
IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 and IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 could allow a remote attacker to conduct phishing attacks, caused by an open redirect vulnerability. An attacker could exploit this vulnerability using a specially crafted request to redirect a victim to arbitrary Web sites.
Published: 2026-07-17
Score: 3.1 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An open redirect flaw in IBM Verify Identity Access and IBM Security Verify Access allows a remote attacker to direct victims to arbitrary URLs by issuing a specially crafted request. Because the redirect is not validated, a user who follows the redirected link may be led to a malicious site that could phish credentials or deliver malware. This vulnerability is defined as CWE-601 and primarily compromises the integrity of user trust, potentially exposing confidential information if the phishing attempt succeeds.

Affected Systems

IBM Verify Identity Access versions 11.0 through 11.0.2 and IBM Verify Identity Access Container versions 11.0 through 11.0.2 are impacted. IBM Security Verify Access versions 10.0 through 10.0.9.1 and IBM Security Verify Access Container versions 10.0 through 10.0.9.1 are also affected.

Risk and Exploitability

The vulnerability carries a CVSS score of 3.1, indicating low severity, and an EPSS score of less than 1%, suggesting a very low current exploitation probability. It is not listed in the CISA KEV catalog. The likely attack vector involves a remote attacker sending an HTTP request to the vulnerable application; the flaw is exploitable over the network, but a victim must still engage with the redirected URL to realize the phishing outcome.

Generated by OpenCVE AI on August 3, 2026 at 02:43 UTC.

Remediation

Vendor Solution

IBM encourages customers to update their systems promptly.Appliance:Affected Products and VersionsFix availabilityIBM Verify Identity Access 11.0 - 11.0.2Download IBM Verify Identity Access v11.0.3IBM Security Verify Access 10.0 0 - 10.0.9.1Download IBM Security Verify Access v10.0.9.2Container:Container Download


OpenCVE Recommended Actions

  • Download and install IBM Verify Identity Access v11.0.3 to patch all 11.0.x installations.
  • Download and install IBM Verify Identity Access Container v11.0.3 to patch all 11.0.x container deployments.
  • Download and install IBM Security Verify Access v10.0.9.2 to patch all 10.0.x installations.
  • Download and install IBM Security Verify Access Container v10.0.9.2 to patch all 10.0.x container deployments.
  • Restrict allowed redirect URLs to known trusted domains or remove the open redirect feature from the application configuration as a temporary mitigation.

Generated by OpenCVE AI on August 3, 2026 at 02:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 17 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Description IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 and IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 could allow a remote attacker to conduct phishing attacks, caused by an open redirect vulnerability. An attacker could exploit this vulnerability using a specially crafted request to redirect a victim to arbitrary Web sites.
Title Security vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify Access
First Time appeared Ibm
Ibm security Verify Access
Ibm security Verify Access Container
Ibm verify Identity Access
Ibm verify Identity Access Container
Weaknesses CWE-601
CPEs cpe:2.3:a:ibm:security_verify_access:10.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:security_verify_access:10.0.9.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:security_verify_access:10.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:security_verify_access_container:10.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:security_verify_access_container:10.0.9.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:security_verify_access_container:10.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:verify_identity_access:11.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:verify_identity_access:11.0.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:verify_identity_access:11.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:verify_identity_access_container:11.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:verify_identity_access_container:11.0.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:verify_identity_access_container:11.0:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm security Verify Access
Ibm security Verify Access Container
Ibm verify Identity Access
Ibm verify Identity Access Container
References
Metrics cvssV3_1

{'score': 3.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N'}


Subscriptions

Ibm Security Verify Access Security Verify Access Container Verify Identity Access Verify Identity Access Container
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-07-20T13:59:14.531Z

Reserved: 2026-04-28T20:43:22.842Z

Link: CVE-2026-7364

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T02:45:03Z

Weaknesses
  • CWE-601

    URL Redirection to Untrusted Site ('Open Redirect')