IBM Verify Identity Access and IBM Security Verify Access Reverse Proxy HTTP Request Smuggling Vulnerability

Vulnerability

A vulnerability exists in IBM Verify Identity Access Container versions 11.0 through 11.0.2, IBM Security Verify Access Container versions 10.0 through 10.0.9.1, IBM Verify Identity Access versions 11.0 through 11.0.2, and IBM Security Verify Access versions 10.0 through 10.0.9.1. This vulnerability could allow a remote attacker to access sensitive information by exploiting an inconsistent interpretation of an HTTP request by a reverse proxy.

Impact

Exploitation of this vulnerability could lead to unauthorized access to sensitive information.

Remediation

Users are encouraged to update to IBM Verify Identity Access v11.0.2 IF1 or IBM Security Verify Access v10.0.9.1 IF1. Instructions for downloading these versions are available on the IBM Support Fix Central website. For container users, the latest version can be downloaded from the IBM Security Verify Access documentation site.

Added: Apr 1, 2026, 9:58 PM
Updated: Apr 1, 2026, 9:58 PM

Vulnerability Rating

Custom Algorithm
spread
3.4
impact
2.5
exploitability
6.6
remediation
7.7
relevance
5.1
threat
0.0
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.