IBM Security Verify Access Appliance and Container 10.0.0 through 10.0.8 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned. This information could be used in further attacks against the system.
2025-02-04T18:15:34.723
2025-08-05T13:51:02.927
Analyzed
CVSSv3.1: 5.3 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | ibm | security_verify_access | ≤ 10.0.8 | Yes |
Application | ibm | verify_identity_access | ≤ 10.0.8 | Yes |