Executive brief
IBM Security Verify Identity Access is an identity and access management (IAM) solution that acts as a reverse proxy to control and authenticate requests to protected services. A vulnerability allows attackers to inject malicious parameters into requests forwarded to third-party services, potentially bypassing security controls or manipulating the behavior of downstream applications without authentication.
Technical details
This vulnerability is an improper neutralization of special elements in output used by a downstream component (CWE-74, injection class). The IBM Security Verify Identity Access reverse proxy fails to properly sanitize or validate parameters before forwarding requests to backend services. An attacker with network access can inject arbitrary parameters into requests, allowing manipulation of third-party service calls. The attack requires only network access with no authentication or user interaction; however, the attack complexity is rated high (AC:H). Successful exploitation can lead to information disclosure and integrity violations against downstream systems.
Affected products
- IBM Security Verify Identity Access
Timeline
- 2026-09-15: disclosed