ZeroHour

CVE-2026-11929

moderate

Weak Cryptographic Validation in IBM Security Verify Identity Access Reverse Proxy

CVSS 3.1
7.5 high
EPSS
Published
()
Modified
AI analysis

The Reverse Proxy component of IBM Security Verify Identity Access, when deployed in certain configurations, performs weaker-than-expected cryptographic validation of user-supplied data (CWE-327). Because the flaw is remotely exploitable over the network with no authentication, privileges, or user interaction required (AV:N/AC:L/PR:N/UI:N), an attacker who can reach the proxy may be able to decrypt, forge, or otherwise infer sensitive data such as session tokens or credentials handled by the proxy. The impact is limited to confidentiality (C:H/I:N/A:N), rated CVSS 3.1 7.5 (high) — attackers gain information disclosure rather than code execution or service disruption. Organizations running the SVI Reverse Proxy in an affected configuration, typically enterprises exposing web SSO and authentication endpoints to the internet, are at risk. There is no known public proof of concept and no confirmed exploitation in the wild as of this writing.

What to do: Apply IBM's fixed versions or interim fixes per the official security bulletin, confirming affected version ranges with IBM support since the advisory does not enumerate them. Audit reverse proxy cryptographic settings — disable deprecated ciphers/algorithms on SSL profiles and junctions, enforce TLS 1.2+, and ensure strong validation of user-supplied cryptographic material. Review reverse proxy and audit logs for repeated malformed or anomalous client requests that could indicate probing of the weak validation path.

Affected
IBM Security Verify Identity Access Reverse Proxy (reverse proxy component of IBM's enterprise identity and access managemen
Estimated exposure
moderate≈ low thousands of internet-facing reverse proxy instances across thousands of enterprise/government deployments — SVI (formerly IBM Security Access Manager) is enterprise IAM software sold to large organizations, and public internet scans historically show on the order of a few thousand exposed ISAM/SVI proxy endpoints — an order-of-magnitude…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

IBM Security Verify Identity Access Reverse Proxy in certain configurations may provide weaker than expected cryptographic validation of user supplied data.

Weakness
CWE-327
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.