9.8
CVE-2024-10905
- EPSS 0.95%
- Veröffentlicht 02.12.2024 15:15:10
- Zuletzt bearbeitet 12.11.2025 15:49:07
- Erkennungen
IdentityIQ Improper Access Control VulnerabilityIdentityIQ Improper Access Control Vulnerability
IdentityIQ 8.4 and all 8.4 patch levels prior to 8.4p2, IdentityIQ 8.3 and all 8.3 patch levels prior to 8.3p5, IdentityIQ 8.2 and all 8.2 patch levels prior to 8.2p8, and all prior versions allow HTTP/HTTPS access to static content in the IdentityIQ application directory that should be protected.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Sailpoint ≫ Identityiq Version < 8.2
Sailpoint ≫ Identityiq Version 8.2 Update -
Sailpoint ≫ Identityiq Version 8.2 Update patch1
Sailpoint ≫ Identityiq Version 8.2 Update patch2
Sailpoint ≫ Identityiq Version 8.2 Update patch4
Sailpoint ≫ Identityiq Version 8.2 Update patch5
Sailpoint ≫ Identityiq Version 8.2 Update patch7
Sailpoint ≫ Identityiq Version 8.3 Update -
Sailpoint ≫ Identityiq Version 8.3 Update patch1
Sailpoint ≫ Identityiq Version 8.3 Update patch2
Sailpoint ≫ Identityiq Version 8.3 Update patch4
Sailpoint ≫ Identityiq Version 8.4 Update -
Sailpoint ≫ Identityiq Version 8.4 Update patch1
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.95% | 0.569 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| psirt@sailpoint.com | 10 | 3.9 | 6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
|
CWE-66 Improper Handling of File Names that Identify Virtual Resources
The product does not handle or incorrectly handles a file name that identifies a "virtual" resource that is not directly specified within the directory that is associated with the file name, causing the product to perform file-based operations on a resource that is not a file.
https://www.sailpoint.com/security-advisories/identityiq-improper-access-control-vulnerability-cve-2024-10905