Cross-Site Request Forgery Vulnerability in IBM Security Verify Access Appliance
CVE-2024-35138

6.5MEDIUM

Key Information:

Vendor
IBM
Vendor
CVE Published:
4 February 2025

Summary

The IBM Security Verify Access Appliance and Container versions 10.0.0 through 10.0.8 are susceptible to a cross-site request forgery attack. This vulnerability allows an attacker to perform unauthorized actions by exploiting the trust of the victim’s browser against the legitimate website. If the victim is authenticated on the site, the attacker can transmit malicious requests, leading to potential unauthorized changes and actions within the application.

Affected Version(s)

Security Verify Access Appliance 10.0.0 <= 10.0.8

Security Verify Access Container 10.0.0 <= 10.0.8

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.