- Description
- IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 contains a input validation vulnerability in the management interface that allows already privileged attackers to execute additional operations by crafting a malicious HTTP request.
- Source
- psirt@us.ibm.com
- NVD status
- Analyzed
- Products
- security_verify_access, verify_identity_access, verify_identity_access_container
CVSS 3.1
- Type
- Secondary
- Base score
- 7.2
- Impact score
- 5.9
- Exploitability score
- 1.2
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- Severity
- HIGH
- psirt@us.ibm.com
- CWE-78
- Hype score
- Not currently trending
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:ibm:security_verify_access:*:*:*:*:*:*:*:*",
"matchCriteriaId": "7B471197-37E5-4B7D-AF9E-0F9A3EEA4B6B",
"versionEndIncluding": "10.0.9.2",
"versionStartIncluding": "10.0.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:ibm:security_verify_access:10.0.9.2:interim_fix1:*:*:*:*:*:*",
"matchCriteriaId": "D58DD2C2-F5CA-4A10-933B-4CB149CEB811",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:ibm:verify_identity_access:*:*:*:*:*:*:*:*",
"matchCriteriaId": "5899B235-F061-4026-A0C1-AB506035D604",
"versionEndIncluding": "11.0.3",
"versionStartIncluding": "11.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:ibm:verify_identity_access_container:*:*:*:*:*:*:*:*",
"matchCriteriaId": "A25819B9-7101-415B-93F8-27FB72BA5C3D",
"versionEndIncluding": "11.0.3.0",
"versionStartIncluding": "11.0.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]