CVE-2025-10280
- EPSS 0.05%
- Veröffentlicht 03.11.2025 16:35:56
- Zuletzt bearbeitet 12.11.2025 14:49:56
IdentityIQ 8.5, IdentityIQ 8.4 and all 8.4 patch levels prior to 8.4p4, IdentityIQ 8.3 and all 8.3 patch levels including 8.3p5, and all prior versions allows some IdentityIQ web services that provide non-HTML content to be accessed via a URL path th...
CVE-2024-10905
- EPSS 0.89%
- Veröffentlicht 02.12.2024 15:15:10
- Zuletzt bearbeitet 12.11.2025 15:49:07
IdentityIQ 8.4 and all 8.4 patch levels prior to 8.4p2, IdentityIQ 8.3 and all 8.3 patch levels prior to 8.3p5, IdentityIQ 8.2 and all 8.2 patch levels prior to 8.2p8, and all prior versions allow HTTP/HTTPS access to static content in the IdentityIQ...
CVE-2024-2227
- EPSS 0.61%
- Veröffentlicht 22.03.2024 16:15:09
- Zuletzt bearbeitet 12.11.2025 20:20:36
This vulnerability allows access to arbitrary files in the application server file system due to a path traversal vulnerability in JavaServer Faces (JSF) 2.2.20 documented in CVE-2020-6950. The remediation for this vulnerability contained in this sec...
CVE-2024-2228
- EPSS 0.21%
- Veröffentlicht 22.03.2024 16:15:09
- Zuletzt bearbeitet 12.11.2025 20:19:38
This vulnerability allows an authenticated user to perform a Lifecycle Manager flow or other QuickLink for a target user outside of the defined QuickLink Population.
CVE-2024-1714
- EPSS 0.08%
- Veröffentlicht 21.02.2024 17:15:09
- Zuletzt bearbeitet 30.09.2025 16:56:44
An issue exists in all supported versions of IdentityIQ Lifecycle Manager that can result if an entitlement with a value containing leading or trailing whitespace is requested by an authenticated user in an access request.
CVE-2023-32217
- EPSS 0.98%
- Veröffentlicht 05.06.2023 04:15:10
- Zuletzt bearbeitet 25.02.2026 17:20:50
IdentityIQ 8.3 and all 8.3 patch levels prior to 8.3p3, IdentityIQ 8.2 and all 8.2 patch levels prior to 8.2p6, IdentityIQ 8.1 and all 8.1 patch levels prior to 8.1p7, IdentityIQ 8.0 and all 8.0 patch levels prior to 8.0p6 allow an authenticated user...
CVE-2022-45435
- EPSS 0.22%
- Veröffentlicht 31.01.2023 15:15:08
- Zuletzt bearbeitet 21.11.2024 07:29:15
IdentityIQ 8.3 and all 8.3 patch levels prior to 8.3p2, IdentityIQ 8.2 and all 8.2 patch levels prior to 8.2p5, IdentityIQ 8.1 and all 8.1 patch levels prior to 8.1p7, IdentityIQ 8.0 and all 8.0 patch levels prior to 8.0p6, and all prior versions all...
CVE-2022-46835
- EPSS 0.56%
- Veröffentlicht 31.01.2023 15:15:08
- Zuletzt bearbeitet 21.11.2024 07:31:08
IdentityIQ 8.3 and all 8.3 patch levels prior to 8.3p2, IdentityIQ 8.2 and all 8.2 patch levels prior to 8.2p5, IdentityIQ 8.1 and all 8.1 patch levels prior to 8.1p7, IdentityIQ 8.0 and all 8.0 patch levels prior to 8.0p6 allow access to arbitrary f...