IBM Security Verify Access Vulnerability Could Lead to Phishing Attacks

CVE-2024-35133
8.2HIGH

Key Information

Vendor
IBM
Status
Security Verify Access
Security Verify Access Docker
Vendor
CVE Published:
29 August 2024

Badges

👾 Exploit Exists🔴 Public PoC

Summary

IBM Security Verify Access 10.0.0 through 10.0.8 OIDC Provider could allow a remote authenticated attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim.

Affected Version(s)

Security Verify Access <= 10.0.8

Security Verify Access Docker <= 10.0.8

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • 👾

    Exploit exists.

  • Risk change from: 8.2 to: 6.8 - (MEDIUM)

  • Risk change from: 8.2 to: 6.8 - (MEDIUM)

  • Vulnerability published.

  • Vulnerability Reserved.

Collectors

NVD DatabaseMitre Database1 Proof of Concept(s)
.