Description
An improper access control was identified in the Identity Security Cloud (ISC) message server API that allowed an authenticated user to exfiltrate job processing metadata (opaque messageIDs, work queue depth and counts) for other tenants.
Published: 2024-05-15
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

This issue has been resolved. No further action is needed.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2024-31907 An improper access control was identified in the Identity Security Cloud (ISC) message server API that allowed an authenticated user to exfiltrate job processing metadata (opaque messageIDs, work queue depth and counts) for other tenants.
History

No history.

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: SailPoint

Published:

Updated: 2024-08-01T20:05:08.372Z

Reserved: 2024-04-04T16:14:51.162Z

Link: CVE-2024-3317

cve-icon Vulnrichment

Updated: 2024-08-01T20:05:08.372Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-05-15T16:15:10.727

Modified: 2024-11-21T09:29:22.997

Link: CVE-2024-3317

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses