Impact
The vulnerability involves an insecure deserialization of untrusted data, allowing a remote unauthenticated attacker to execute arbitrary code. This flaw is identified as CWE‑502. Because the attacker can run code with system privileges, confidentiality, integrity, and availability are at severe risk.
Affected Systems
Affected versions include IBM Security Verify Access from 10.0 through 10.0.9.2 and IBM Verify Identity Access from 11.0 through 11.0.3, including the corresponding container offerings. The vendor provides updates: IBM Verify Identity Access v11.0.3.1 and IBM Security Verify Access v10.0.9.3.
Risk and Exploitability
The CVSS score is 9.8, indicating critical severity. The EPSS score is not available, but the issue is not yet listed in the CISA KEV catalog. Likely attack vector is the delivery of crafted serialized data over a network interface that is accessible without authentication; such a payload can trigger code execution as described. The risk remains high until the defined patches are applied.
OpenCVE Enrichment