8.5

CVE-2026-1342

Medienbericht

Security Vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify Access

IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 and IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 could allow a locally authenticated user to execute malicious scripts from outside of its control sphere.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
IbmSecurity Verify Access Version >= 10.0.0 <= 10.0.9.1
IbmSecurity Verify Access Container Version >= 10.0.0.0 <= 10.0.9.1
IbmVerify Identity Access Version >= 11.0.0.0 <= 11.0.2.0
IbmVerify Identity Access Container Version >= 11.0.0.0 <= 11.0.2.0
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.02% 0.042
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.9 2 5.3
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L
psirt@us.ibm.com 8.5 2.5 5.3
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:L
CWE-829 Inclusion of Functionality from Untrusted Control Sphere

The product imports, requires, or includes executable functionality (such as a library) from a source that is outside of the intended control sphere.