IBM Security Verify Access Vulnerability Could Lead to Phishing Attacks
Key Information
- Vendor
- IBM
- Status
- Security Verify Access
- Security Verify Access Docker
- Vendor
- CVE Published:
- 29 August 2024
Badges
Summary
IBM Security Verify Access 10.0.0 through 10.0.8 OIDC Provider could allow a remote authenticated attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim.
Affected Version(s)
Security Verify Access <= 10.0.8
Security Verify Access Docker <= 10.0.8
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
CVSS V3.1
Timeline
- 👾
Exploit exists.
Risk change from: 8.2 to: 6.8 - (MEDIUM)
Risk change from: 8.2 to: 6.8 - (MEDIUM)
Vulnerability published.
Vulnerability Reserved.