Executive brief
IBM Verify Identity Access is an identity and access management platform used to authenticate and authorize users to enterprise applications. Due to insufficient validation of incoming request resources, a remote attacker can trigger a denial of service condition that crashes or hangs the service, making it unavailable to legitimate users.
Technical details
The vulnerability is a result of uncontrolled recursion (CWE-674) in IBM Verify Identity Access that occurs due to insufficient validation of incoming request resources. The flaw is remotely exploitable over the network without requiring authentication or user interaction (CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U). An unauthenticated remote attacker can send specially crafted requests that cause the application to enter an infinite or deeply nested recursive loop, exhausting system resources and resulting in a denial of service. IBM has issued a security bulletin addressing this vulnerability.
Affected products
- IBM Verify Identity Access
Timeline
- 2026-09-14: disclosed