IBM Security Verify Access
cpe:2.3:a:ibm:security_verify_access:*:*:*:*:*:*:*
- >= 10.0, <= 10.0.9.1
A vulnerability exists in IBM Verify Identity Access Container versions 11.0 through 11.0.2, IBM Security Verify Access Container versions 10.0 through 10.0.9.1, IBM Verify Identity Access versions 11.0 through 11.0.2, and IBM Security Verify Access versions 10.0 through 10.0.9.1. This vulnerability could allow a remote attacker to access sensitive information. The issue arises from an inconsistent interpretation of an HTTP request by a reverse proxy, which could be exploited to smuggle HTTP requests or responses.
Exploitation of this vulnerability could lead to unauthorized access to sensitive information.
Users are encouraged to update to IBM Verify Identity Access v11.0.2 IF1 or IBM Security Verify Access v10.0.9.1 IF1. For container users, instructions are available in the IBM Security Verify Access documentation.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.