Sceawere

Vulnerability Detail

CVE-2026-11937UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

IBM Verify Access Denial of Service

Vulnerability Metadata

Severity
Low
Score / CVSS
3.1
Creation Date
2h ago
Vendor
IBM
Product
Security Verify Access
Attack Type
CWE-416 Use After Free
Vector String
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L
Attack Complexity
HIGH

Narrative and Response

Description

IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 and IBM Security Verify Access Container 10.0 through 10.0.9.2 Reverse Proxy in certain configurations is vulnerable to a denial of service attack.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "3.1",
  "pubDate": "2026-08-12T20:17:33.390Z",
  "pubdate": "2026-08-12T20:17:33.390Z",
  "executiveSummary": "A denial of service vulnerability exists within the Reverse Proxy component of IBM Security Verify Access 10.0 through 10.0.9.2, IBM Verify Identity Access 11.0 through 11.0.3, IBM Verify Identity Access Container 11.0 through 11.0.3, and IBM Security Verify Access Container 10.0 through 10.0.9.2 in certain configurations.\nThe vulnerability allows an unauthenticated remote attacker to cause a denial of service condition affecting the availability of the targeted system.\nSuccessful exploitation disrupts standard operations of the reverse proxy, potentially leading to service outages for protected downstream applications.\nThe risk implication is high regarding operational availability, as it targets core proxy routing and inspection capabilities.\nAttack capabilities require network access to the vulnerable reverse proxy listener in specific non-default or targeted configurations, driving the operational impact.",
  "technicalDetails": "The vulnerability resides in the Reverse Proxy component of the affected IBM security and identity products. The root cause stems from improper handling of specific request structures or patterns under certain configurations, leading to resource exhaustion or process crashes.\nExploitation occurs when an attacker crafts a malicious payload or sequence of network requests sent directly to the reverse proxy listener. Upon parsing or processing the input within the affected component, the application encounters an unhandled exception or consumes excessive system resources.\nThe attack flow begins with the attacker establishing a network connection to the exposed reverse proxy interface. The attacker transmits the malformed input sequence without requiring prior authentication or elevated privileges.\nThe vulnerable component processes the request, triggering the flaw that disrupts normal thread execution or memory management. Consequently, the reverse proxy service becomes unresponsive, hangs, or terminates unexpectedly, halting all proxy services for legitimate clients.\nAffected software versions include IBM Security Verify Access 10.0 through 10.0.9.2, IBM Verify Identity Access 11.0 through 11.0.3, IBM Verify Identity Access Container 11.0 through 11.0.3, and IBM Security Verify Access Container 10.0 through 10.0.9.2.\nNetwork exposure is restricted to the ports configured for the reverse proxy services, and exploitation requires no authentication or special privileges. Post-exploitation impact is strictly limited to availability degradation or complete denial of service of the affected proxy instance."
}
CVE-2026-11937: IBM Verify Access Denial of Service (LOW Severity, CVSS: 3.1) - Sceawere