CVE-2026-12004
EUVD-2026-5754112.08.2026, 20:17
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 contains a format string injection vulnerability in the management interface that allows attackers to cause denial of service and information disclosure by crafting a malicious HTTP request.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| ibm | security_verify_access | 10.0.0 ≤ 𝑥 ≤ 10.0.9.2 |
| ibm | security_verify_access | 10.0.9.2:interim_fix1 |
| ibm | verify_identity_access | 11.0 ≤ 𝑥 ≤ 11.0.3 |
| ibm | verify_identity_access_container | 11.0.0.0 ≤ 𝑥 ≤ 11.0.3.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration