IBM Security Verify Access Vulnerability Could Lead to Phishing Attacks
CVE-2024-35133
Key Information
- Vendor
- IBM
- Status
- Security Verify Access
- Security Verify Access Docker
- Vendor
- CVE Published:
- 29 August 2024
Badges
Summary
IBM Security Verify Access 10.0.0 through 10.0.8 OIDC Provider could allow a remote authenticated attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim.
Affected Version(s)
Security Verify Access <= 10.0.8
Security Verify Access Docker <= 10.0.8
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
Refferences
CVSS V3.1
Timeline
- 🔴
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved