Security Verify Access

Vendor:

First CVE: Oct 12, 2020 · Active for 5 years

90
Total CVEs
More Total CVEs than 99% of tracked products
12.9
Avg CVEs / Year
Higher CVE frequency than 97% of tracked products
6.8
Avg CVSS
Higher Avg CVSS than 36% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Security Verify Access over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 12, 2020
5 years ago
Most Recent CVE
Apr 23, 2026
94 days ago

CVE Severity & Scoring

Security Verify Access90 CVEs
All CVEs352,719 CVEs
LowMediumHighCritical
Attack Vector
Local21 (23.3%)
Network65 (72.2%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network4 (4.4%)
Attack Complexity
Low82 (91.1%)
High8 (8.9%)
Unknown0 (0.0%)
User Interaction
None77 (85.6%)
Unknown0 (0.0%)
Required13 (14.4%)
Privileges Required
Low23 (25.6%)
High13 (14.4%)
None54 (60.0%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (90 CVEs).

90 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 and IBM Verify Identity Access 11.0 through 11.0.2 and IBM S
Apr 8, 20269.335NONO
IBM Security Verify Access 10.0.0 through 10.0.9, 11.0.0, IBM Verify Identity Access Container 10.0.0 through 10.0.9, and 11.0.0, under certain configurations, contains hard-coded
Oct 13, 20259.833NONO
IBM Security Verify Access and IBM Security Verify Access Docker 10.0.0.0 through 10.0.9.0 and 11.0.0.0 through 11.0.1.0 could allow a locally authenticated user to escalate their
Oct 6, 20259.333NONO
IBM Security Verify Access 10.0.0 through 10.0.8 OIDC Provider could allow a remote authenticated attacker to conduct phishing attacks, using an open redirect attack. By persuading
Aug 29, 20248.233NOYES
IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 and IBM Verify Identity Access 11.0 through 11.0.2 and IBM S
Apr 8, 20268.532NONO
IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 and IBM Verify Identity Access 11.0 through 11.0.2 and IBM S
Apr 1, 20269.832NONO
IBM Security Verify Access 10.0.0.0, 10.0.1.0 and 10.0.2.0 with the advanced access control authentication service enabled could allow an attacker to authenticate as any user on th
Feb 2, 20229.831NONO
IBM Security Verify Access and IBM Security Verify Access Docker 10.0.0.0 through 10.0.9.0 and 11.0.0.0 through 11.0.1.0 could allow a locally authenticated user to execute malic
Oct 6, 20258.528NONO
IBM Security Verify Access Appliance 10.0.0 through 10.0.8 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authenticat
Nov 29, 20249.828NONO
IBM Security Verify Access Appliance 10.0.0 through 10.0.8 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authenticat
Nov 29, 20249.828NONO

Exploit Exposure

Signals from CVEs in this product scope (90 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
1.1% of CVEs· 87th percentile

Social Chatter

Signals from CVEs in this product scope (90 CVEs).

Media Mentions

Signals from CVEs in this product scope (90 CVEs).

Top CNAs Publishing CVEs For Security Verify Access

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
20.0746.01.2%00
11.0.017.80.2%00
10.0.9.038.40.2%00
10.0.615.50.1%00
10.0.517.51.5%00
10.0.4.016.50.4%00
10.0.417.51.5%00
10.0.3.056.70.5%00
10.0.327.01.1%00
10.0.2.0116.50.8%00
10.0.227.01.1%00
10.0.1.0116.50.8%00
10.0.127.01.1%00
10.0.0.056.70.5%00
10.0.0295.80.8%00