Impact
The vulnerability is a cross‑site scripting flaw that permits an authenticated user to embed arbitrary JavaScript in the web UI, allowing the attacker to modify application behavior and potentially expose credentials within a trusted session (CWE‑79).
Affected Systems
IBM Security Verify Access versions 10.0 through 10.0.9.2, IBM Verify Identity Access versions 11.0 through 11.0.3, and their container deployments are affected. Updated releases v10.0.9.3 for Security Verify Access and v11.0.3.1 for Verify Identity Access contain the fix.
Risk and Exploitability
With a CVSS score of 5.4 the flaw carries moderate severity and is not listed in CISA KEV. Exploitation requires a valid user account that can reach the web console; once authenticated, the attacker can inject malicious scripts that run in the victim’s browser, potentially leaking session data. The vendor advises applying the patches promptly in order to mitigate the risk.
OpenCVE Enrichment