Impact
IBM Verify Identity Access and IBM Security Verify Access can disclose sensitive information to a remote attacker when a detailed technical error message is returned in the browser. The vulnerability does not provide direct code execution or privilege escalation; it simply allows an attacker to obtain details that could be used in subsequent attacks.
Affected Systems
Affected deployments include IBM Verify Identity Access versions 11.0.0 through 11.0.2 and IBM Security Verify Access versions 10.0.0 through 10.0.9.1, in both standard and containerized installations. Container images can be updated to the latest releases following IBM’s documentation link.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. The EPSS score is below 1%, reflecting a low current probability of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is a remote HTTP request that triggers the application to return a detailed error response. While there is no direct code execution or privilege escalation, the leaked information could facilitate more targeted attacks.
OpenCVE Enrichment