IBM Security Verify Governance Password Policy Vulnerability

Vulnerability

A vulnerability exists in IBM Security Verify Governance version 10.0.2, where the default password policy does not enforce strong password requirements. This weakness can make it easier for attackers to compromise user accounts.

Impact

Exploitation of this vulnerability can lead to unauthorized access to user accounts, allowing attackers to impersonate users or gain access to sensitive information and resources.

Remediation

Users are advised to update to IBM Security Verify Governance version 10.0.2.0-ISS-ISVG-IGVA-FP0005. Instructions for downloading this fix are available on the IBM Support Fix Central website.

Added: Jun 6, 2025, 2:19 AM
Updated: Jun 6, 2025, 2:19 AM

Vulnerability Rating

Custom Algorithm
spread
0.8
impact
5.0
exploitability
7.4
remediation
7.7
relevance
0.2
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.