6.5
CVE-2026-4938
- EPSS 0.17%
- Veröffentlicht 17.07.2026 19:34:14
- Zuletzt bearbeitet 30.07.2026 13:07:59
- Erkennungen
Incorrect Authorization in IBM Verify Identity Access and IBM Security Verify Access
IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 and IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 could allow an attacker with read-only privileges to make unauthorized modifications and deployments outside of their assigned permissions.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ibm ≫ Security Verify Access Version >= 10.0.0 <= 10.0.9.1
Ibm ≫ Security Verify Access Container Version >= 10.0.0.0 <= 10.0.9.1
Ibm ≫ Verify Identity Access Version >= 11.0 <= 11.0.2.0
Ibm ≫ Verify Identity Access Container Version >= 11.0.0.0 <= 11.0.2.0
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.17% | 0.071 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| IBM | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
|
CWE-863 Incorrect Authorization
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
https://www.ibm.com/support/pages/node/7279510