CVE-2026-11904
5.3
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Summary
IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 and IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| IBM | Verify Identity Access | 11.0 <= 11.0.2 | affected |
| IBM | Security Verify Access | 10.0 <= 10.0.9.1 | affected |
| IBM | Verify Identity Access Container | 11.0 <= 11.0.2 | affected |
| IBM | Security Verify Access Container | 10.0 <= 10.0.9.1 | affected |
Weaknesses
- CWE-209: CWE-209 Generation of Error Message Containing Sensitive Information
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: yes
- Technical Impact: partial
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.