Executive brief
IBM Verify Identity Access is an identity and access management system used to authenticate users and control network access. An open redirect vulnerability allows attackers to craft malicious links that appear to direct users to a trusted IBM login page but actually redirect them to attacker-controlled phishing sites, enabling credential theft and further attacks.
Technical details
This is an open redirect vulnerability in IBM Verify Identity Access that fails to properly validate redirect parameters in HTTP responses. An unauthenticated remote attacker can craft a specially crafted URL that, when clicked by a user, redirects to an arbitrary external website while the URL bar initially displays the trusted IBM domain. The vulnerability requires user interaction (clicking a malicious link) and can be used in phishing campaigns to harvest credentials or deliver additional malware. Patch availability has not been explicitly confirmed in the provided reference.
Affected products
- IBM Verify Identity Access
Timeline
- 2026-09-14: disclosed