IBM Security Verify Access
cpe:2.3:a:ibm:security_verify_access:*:*:*:*:*:*:*
- >= 10.0, <= 10.0.9.1
A vulnerability allowing an unauthenticated user to execute arbitrary commands with limited user privileges has been identified in IBM Verify Identity Access Container versions 11.0 through 11.0.2, IBM Security Verify Access Container versions 10.0 through 10.0.9.1, IBM Verify Identity Access versions 11.0 through 11.0.2, and IBM Security Verify Access versions 10.0 through 10.0.9.1. This issue arises from improper validation of user-supplied input, which could potentially be exploited to execute commands on the system.
Exploitation of this vulnerability could lead to unauthorized command execution on the system with reduced user privileges.
Users are advised to update to IBM Verify Identity Access v11.0.2 IF1 or IBM Security Verify Access v10.0.9.1 IF1. For container users, instructions are available in the IBM Security Verify Access documentation.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.