Impact
The vulnerability arises from the deserialization of untrusted data, allowing a remote unauthenticated attacker to execute arbitrary code on the system. It is a classic deserialization flaw identified as CWE-502, which can compromise confidentiality, integrity, and availability of the affected services.
Affected Systems
Affected IBM products include IBM Security Verify Access versions 10.0 through 10.0.9.2 and IBM Verify Identity Access versions 11.0 through 11.0.3, as well as their corresponding container-enabled editions. IBM has released patches: IBM Verify Identity Access v11.0.3.1 and IBM Security Verify Access v10.0.9.3.
Risk and Exploitability
The CVSS score of 9.8 indicates critical severity. With no EPSS data available and the vulnerability not listed in the CISA KEV catalog, the nominal exploit probability is unknown, but the remote nature and power to run code make this a high‑risk issue. An attacker can send a crafted serialized payload over an unauthenticated channel to exploit the flaw.
OpenCVE Enrichment