CVE-2023-25927
Severity CVSS v4.0:
Pending analysis
Type:
CWE-20
Input Validation
Publication date:
12/05/2023
Last modified:
03/11/2025
Description
IBM Security Verify Access 10.0.0, 10.0.1, 10.0.2, 10.0.3, 10.0.4, and 10.0.5 could allow an attacker to crash the webseald process using specially crafted HTTP requests resulting in loss of access to the system. IBM X-Force ID: 247635.
Impact
Base Score 3.x
6.50
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:ibm:security_verify_access:10.0.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:ibm:security_verify_access:10.0.1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:ibm:security_verify_access:10.0.2:*:*:*:*:*:*:* | ||
| cpe:2.3:a:ibm:security_verify_access:10.0.3:*:*:*:*:*:*:* | ||
| cpe:2.3:a:ibm:security_verify_access:10.0.4:*:*:*:*:*:*:* | ||
| cpe:2.3:a:ibm:security_verify_access:10.0.5:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://exchange.xforce.ibmcloud.com/vulnerabilities/247635
- https://https://www.ibm.com/support/pages/node/6989653
- https://www.ibm.com/support/pages/node/6989653?_ga=2.22490043.1644592052.1684753176-785517468.1677620719
- http://seclists.org/fulldisclosure/2024/Nov/0
- http://seclists.org/fulldisclosure/2024/Nov/1
- https://exchange.xforce.ibmcloud.com/vulnerabilities/247635
- https://https://www.ibm.com/support/pages/node/6989653



