Executive brief
IBM Verify Identity Access is a solution used by organizations to manage user identities and control access to applications. A security flaw in this product could allow an attacker to trick users into visiting malicious websites by clicking on a link that appears to belong to a trusted corporate portal. This technique is commonly used in phishing campaigns to steal user credentials or deliver malware.
Technical details
An open redirect vulnerability (CWE-601) exists in IBM Verify Identity Access and IBM Security Verify Access (including containerized versions). The flaw is caused by improper validation of user-supplied input used in redirection targets. A remote, unauthenticated attacker can exploit this by crafting a URL that, when clicked by a victim, redirects them from the trusted IBM Verify domain to an arbitrary external malicious website. While the attack requires user interaction and has a high complexity (AC:H), it can be used to increase the perceived legitimacy of phishing attempts. Affected versions include 10.0.x up to 10.0.9.1 and 11.0.x up to 11.0.2.
Affected products
- IBM Verify Identity Access 11.0 through 11.0.2
- IBM Security Verify Access 10.0 through 10.0.9.1
- IBM Verify Identity Access Container 11.0 through 11.0.2
- IBM Security Verify Access Container 10.0 through 10.0.9.1
Timeline
- 2026-07-17: disclosed
- 2026-07-17: advisory