Impact
IBM Security Verify Access versions 10.0 through 10.0.9.2 and IBM Verify Identity Access versions 11.0 through 11.0.3 are vulnerable to cross‑site request forgery. This flaw allows a malicious actor to trick a logged‑in user into sending unauthorized requests that the site trusts, potentially leading to unintended state changes, data exposure, or other unauthorised actions.
Affected Systems
Affected vendors include IBM with products Security Verify Access and Verify Identity Access, both in appliance and container editions. Specific vulnerable releases are Security Verify Access 10.0 to 10.0.9.2 and Verify Identity Access 11.0 to 11.0.3. Installed versions should be compared against the official fix releases: Security Verify Access v10.0.9.3 and Verify Identity Access v11.0.3.1.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate severity risk. The exploitation requires a user to visit a malicious page while authenticated, making it an indirect, user‑interaction requirement. EPSS score is not listed in the CISA KEV catalog, suggesting no known widespread exploitation at this time. Nevertheless, because CSRF can be bypassed with social engineering or compromised network traffic, organizations should not ignore it without patching.
OpenCVE Enrichment