IBM Security Verify Access
cpe:2.3:a:ibm:security_verify_access:*:*:*:*:*:*:*
- >= 10.0, <= 10.0.8
A vulnerability in IBM Security Verify Access Appliance and Docker versions 10.0 through 10.0.8 allows remote attackers to enumerate usernames. This issue arises from an observable response discrepancy related to disabled accounts, which can be exploited to infer the existence of certain usernames.
Exploitation of this vulnerability could lead to unauthorized username enumeration, allowing attackers to identify valid user accounts.
Users are advised to update to IBM Security Verify Access version 10.0.9 or IBM Verify Identity Access version 11.0. Instructions for downloading these updates are available on the IBM Support website. For Docker users, log into IBM Cloud Registry and follow the update instructions provided in the IBM Verify Identity Access v11 support page.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.