Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-48307 | IdentityIQ 8.3 and all 8.3 patch levels prior to 8.3p2, IdentityIQ 8.2 and all 8.2 patch levels prior to 8.2p5, IdentityIQ 8.1 and all 8.1 patch levels prior to 8.1p7, IdentityIQ 8.0 and all 8.0 patch levels prior to 8.0p6, and all prior versions allow authenticated users assigned the Identity Administrator capability or any custom capability that contains the SetIdentityForwarding right to modify the work item forwarding configuration for identities other than the ones that should be allowed by Lifecycle Manager Quicklink Population configuration. |
Solution
No solution given by the vendor.
Workaround
Remove the SetIdentityForwarding right from all IdentityIQ capabilities or unassign any capability containing the SetIdentityForwarding right from all identities. In this mitigated state, work item forwarding can still be configured by an identity by modifying user preferences.
Thu, 27 Mar 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: SailPoint
Published:
Updated: 2025-03-27T18:28:39.509Z
Reserved: 2022-11-14T00:00:00.000Z
Link: CVE-2022-45435
Updated: 2024-08-03T14:09:57.045Z
Status : Modified
Published: 2023-01-31T15:15:08.837
Modified: 2024-11-21T07:29:15.307
Link: CVE-2022-45435
No data.
OpenCVE Enrichment
No data.
EUVD