PT-2026-71296 · Ibm · Ibm Verify Identity Access Container+2
CVE-2026-12004
·
Published
2026-08-12
·
Updated
2026-08-12
CVSS v3.1
8.7
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
IBM Security Verify Access versions 10.0 through 10.0.9.2
IBM Verify Identity Access versions 11.0 through 11.0.3
IBM Verify Identity Access Container versions 11.0 through 11.0.3
Description
A format string injection exists in the management interface. This issue allows attackers to cause a denial of service and information disclosure by sending a specially crafted HTTP request. Format string injection occurs when an application improperly uses user-supplied input as the format string argument in certain functions, potentially allowing the attacker to read or write to memory.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
DoS
Use of Externally-Controlled Format String
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ibm Security Verify Access
Verify Identity Access
Ibm Verify Identity Access Container