Impact
The vulnerability allows an authenticated user to trigger a denial of service by sending a specially crafted HTTP query that exploits improper allocation of system resources. This leads to a loss of availability for the affected IBM Verify Identity Access and IBM Security Verify Access services, potentially disabling authentication flows for users and applications that rely on those services.
Affected Systems
IBM Verify Identity Access versions 11.0 through 11.0.3 and IBM Security Verify Access versions 10.0 through 10.0.9.2 are impacted. The corresponding container images for these products are also affected.
Risk and Exploitability
The CVSS base score of 6.5 indicates a moderate severity risk. The EPSS score is not available, so the current likelihood of exploitation is uncertain, but the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a user with valid credentials who can submit HTTP requests to the affected services. Successful exploitation would degrade service availability and could be used as a component of a larger denial of service attack.
OpenCVE Enrichment