Executive brief
IBM Security Verify Directory, a tool used for managing identity and access data, is vulnerable to a security flaw where it fails to properly check the types of files being uploaded. A user with high-level administrative privileges could upload harmful files to the system, which could then be used to launch further attacks against other users or the system itself. This could lead to unauthorized changes to system data or disruptions in service.
Technical details
IBM Security Verify Directory (Container) versions 10.0.0 through 10.0.0.3 are vulnerable to an unrestricted file upload (CWE-434). The root cause is a failure to validate file types during the upload process. An attacker with high privileges (PR:H) can upload malicious files via the network. While the primary impact is on integrity, these files can be leveraged to target other victims or perform secondary attacks against the system infrastructure. IBM has released version 10.0.4 to address this vulnerability.
Affected products
- IBM Security Verify Directory (Container) 10.0.0 - 10.0.0.3
Timeline
- 2026-04-08: advisory: Initial publication by IBM
- 2026-04-22: disclosed: NVD publication date