Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-33546 | IdentityIQ 8.4 and all 8.4 patch levels prior to 8.4p2, IdentityIQ 8.3 and all 8.3 patch levels prior to 8.3p5, IdentityIQ 8.2 and all 8.2 patch levels prior to 8.2p8, and all prior versions allow HTTP/HTTPS access to static content in the IdentityIQ application directory that should be protected. |
Solution
https://community.sailpoint.com/t5/IdentityIQ-Blog/IdentityIQ-Improper-Access-Control-Vulnerability/... https://community.sailpoint.com/t5/IdentityIQ-Blog/IdentityIQ-Improper-Access-Control-Vulnerability/ba-p/261409
Workaround
No workaround given by the vendor.
Mon, 06 Jan 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:sailpoint:identityiq:*:*:*:*:*:*:*:* |
Fri, 06 Dec 2024 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IdentityIQ 8.4 and all 8.4 patch levels prior to 8.4p2, IdentityIQ 8.3 and all 8.3 patch levels prior to 8.3p5, IdentityIQ 8.2 and all 8.2 patch levels prior to 8.2p8, and all prior versions allows HTTP access to static content in the IdentityIQ application directory that should be protected. | IdentityIQ 8.4 and all 8.4 patch levels prior to 8.4p2, IdentityIQ 8.3 and all 8.3 patch levels prior to 8.3p5, IdentityIQ 8.2 and all 8.2 patch levels prior to 8.2p8, and all prior versions allow HTTP/HTTPS access to static content in the IdentityIQ application directory that should be protected. |
Wed, 04 Dec 2024 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Wed, 04 Dec 2024 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Mon, 02 Dec 2024 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sailpoint
Sailpoint identityiq |
|
| CPEs | cpe:2.3:a:sailpoint:identityiq:8.2:-:*:*:*:*:*:* | |
| Vendors & Products |
Sailpoint
Sailpoint identityiq |
|
| Metrics |
ssvc
|
Mon, 02 Dec 2024 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IdentityIQ 8.4 and all 8.4 patch levels prior to 8.4p2, IdentityIQ 8.3 and all 8.3 patch levels prior to 8.3p5, IdentityIQ 8.2 and all 8.2 patch levels prior to 8.2p8, and all prior versions allows HTTP access to static content in the IdentityIQ application directory that should be protected. | |
| Title | IdentityIQ Improper Access Control VulnerabilityIdentityIQ Improper Access Control Vulnerability | |
| Weaknesses | CWE-66 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: SailPoint
Published:
Updated: 2025-01-06T17:42:22.215Z
Reserved: 2024-11-05T20:21:47.258Z
Link: CVE-2024-10905
Updated: 2024-12-02T15:26:13.287Z
Status : Awaiting Analysis
Published: 2024-12-02T15:15:10.240
Modified: 2024-12-06T18:15:22.207
Link: CVE-2024-10905
No data.
OpenCVE Enrichment
No data.
EUVD