CVE-2024-45647: IBM Security Verify Access

Critical severity, CVSS 9.8. EPSS: 0.3% chance of exploitation in the next 30 days.

IBM Security Verify Access 10.0.0 through 10.0.8 and IBM Security Verify Access Docker 10.0.0 through 10.0.8 could allow could an unverified user to change the password of an expired user without prior knowledge of that password.

Affected products

  • IBM Security Verify Access: from 10.0.0, up to and including 10.0.8
  • IBM Security Verify Access Docker: from 10.0.0, up to and including 10.0.8

Published 2025-01-20. Last modified 2026-06-17.