IdentityIQ 8.4 and all 8.4 patch levels prior to 8.4p2, IdentityIQ 8.3 and all 8.3 patch levels prior to 8.3p5, IdentityIQ 8.2 and all 8.2 patch levels prior to 8.2p8, and all prior versions allow HTTP/HTTPS access to static content in the IdentityIQ application directory that should be protected.
Metrics
Affected Vendors & Products
References
History
Fri, 06 Dec 2024 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | IdentityIQ 8.4 and all 8.4 patch levels prior to 8.4p2, IdentityIQ 8.3 and all 8.3 patch levels prior to 8.3p5, IdentityIQ 8.2 and all 8.2 patch levels prior to 8.2p8, and all prior versions allows HTTP access to static content in the IdentityIQ application directory that should be protected. | IdentityIQ 8.4 and all 8.4 patch levels prior to 8.4p2, IdentityIQ 8.3 and all 8.3 patch levels prior to 8.3p5, IdentityIQ 8.2 and all 8.2 patch levels prior to 8.2p8, and all prior versions allow HTTP/HTTPS access to static content in the IdentityIQ application directory that should be protected. |
Wed, 04 Dec 2024 17:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
|
Wed, 04 Dec 2024 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
|
Mon, 02 Dec 2024 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Sailpoint
Sailpoint identityiq |
|
CPEs | cpe:2.3:a:sailpoint:identityiq:8.2:-:*:*:*:*:*:* | |
Vendors & Products |
Sailpoint
Sailpoint identityiq |
|
Metrics |
ssvc
|
Mon, 02 Dec 2024 15:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | IdentityIQ 8.4 and all 8.4 patch levels prior to 8.4p2, IdentityIQ 8.3 and all 8.3 patch levels prior to 8.3p5, IdentityIQ 8.2 and all 8.2 patch levels prior to 8.2p8, and all prior versions allows HTTP access to static content in the IdentityIQ application directory that should be protected. | |
Title | IdentityIQ Improper Access Control VulnerabilityIdentityIQ Improper Access Control Vulnerability | |
Weaknesses | CWE-66 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: SailPoint
Published: 2024-12-02T14:49:51.199Z
Updated: 2024-12-06T17:57:12.682Z
Reserved: 2024-11-05T20:21:47.258Z
Link: CVE-2024-10905
Vulnrichment
Updated: 2024-12-02T15:26:13.287Z
NVD
Status : Awaiting Analysis
Published: 2024-12-02T15:15:10.240
Modified: 2024-12-06T18:15:22.207
Link: CVE-2024-10905
Redhat
No data.