5.3
CVE-2026-11904
- EPSS 0.29%
- Veröffentlicht 30.07.2026 16:54:04
- Zuletzt bearbeitet 12.08.2026 20:07:31
- Erkennungen
Security vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify Access
IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 and IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ibm ≫ Verify Identity Access Version >= 10.0.0.0 <= 10.0.9.1
Ibm ≫ Verify Identity Access Version >= 11.0 <= 11.0.2
Ibm ≫ Verify Identity Access Container Version >= 10.0.0.0 <= 10.0.9.1
Ibm ≫ Verify Identity Access Container Version >= 11.0.0.0 <= 11.0.2
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.29% | 0.215 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| IBM | 5.3 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
|
CWE-209 Generation of Error Message Containing Sensitive Information
The product generates an error message that includes sensitive information about its environment, users, or associated data.
https://www.ibm.com/support/pages/node/7279510