IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 and IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 could allow a locally authenticated user to escalate their privileges to root due to execution with unnecessary privileges than required.
The vulnerability classified as CWE-250 (Execution with Unnecessary Privileges) involves components of IBM Security Verify Access and IBM Verify Identity Access running with higher privileges than actually required for their operation. A locally authenticated user can exploit this to elevate their privileges to root level without needing additional administrative privileges. This affects both containerized and traditional installations of both products.
An attacker with local access to the system can gain full control of the operating system with root privileges, enabling them to read, modify and delete any data, as well as perform further actions in the infrastructure.
Apply patches available from the vendor according to the references (https://www.ibm.com/support/pages/node/7268253). Additionally, it is recommended to restrict local access to systems hosting these products exclusively to trusted and necessary users, and to monitor privilege escalation attempts.
IBM Verify Identity Access versions 11.0 to 11.0.2, IBM Security Verify Access versions 10.0 to 10.0.9.1, IBM Verify Identity Access Container versions 11.0 to 11.0.2, and IBM Security Verify Access Container versions 10.0 to 10.0.9.1.
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HIBM Security Verify Access
APPIbm10.0.0 – 10.0.9.1IBM Security Verify Access Container
APPIbm10.0.0.0 – 10.0.9.1IBM Verify Identity Access
APPIbm11.0.0.0 – 11.0.2.0IBM Verify Identity Access Container
APPIbm11.0.0.0 – 11.0.2.0
Related vulnerabilities
IBM Security Verify Access — privilege escalation do root przez nadmiarowe uprawnienia
IBM Security Verify Access — zakodowane na stałe poświadczenia (hard-coded credentials)
IBM Security Verify Access — zakodowane na stałe poświadczenia (hard-coded credentials)
IBM Security Verify Access — zdalne wykonanie poleceń (command injection)
IBM Security Verify Access — obejście uwierzytelnienia jako dowolny użytkownik