IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 could allow an authenticated user to gain privileges of another user via a specially crafted request.
oryginał ENCVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:NIBM Security Verify Access
APPIbm10.0.9.210.0.0 – 10.0.9.2IBM Verify Identity Access
APPIbm11.0 – 11.0.3IBM Verify Identity Access Container
APPIbm11.0.0.0 – 11.0.3.0
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
Tagi
Container
CWE
Referencje
Powiązane podatności
CVE-2026-1346CRITICAL9.3PL ✓ten sam produkt
Privilege escalation do root w IBM Security Verify Access i Verify Identity Access
CVE-2025-36356CRITICAL9.3PL ✓ten sam produkt
IBM Security Verify Access — privilege escalation do root przez nadmiarowe uprawnienia
CVE-2024-49805CRITICAL9.4PL ✓ten sam produkt
IBM Security Verify Access — zakodowane na stałe poświadczenia (hard-coded credentials)
CVE-2024-49803CRITICAL9.8PL ✓ten sam produkt
IBM Security Verify Access — zdalne wykonanie poleceń (command injection)
CVE-2024-49806CRITICAL9.4PL ✓ten sam produkt
IBM Security Verify Access — zakodowane na stałe poświadczenia (hard-coded credentials)