IdentityIQ
8.5, IdentityIQ 8.4 and all 8.4 patch levels prior to 8.4p4, IdentityIQ 8.3 and
all 8.3 patch levels prior to 8.3p6, and all prior versions allows some
IdentityIQ web services that provide non-HTML content to be accessed via a URL
path that will set the Content-Type to HTML allowing a requesting browser to
interpret content not properly escaped to prevent Cross-Site Scripting (XSS).
            8.5, IdentityIQ 8.4 and all 8.4 patch levels prior to 8.4p4, IdentityIQ 8.3 and
all 8.3 patch levels prior to 8.3p6, and all prior versions allows some
IdentityIQ web services that provide non-HTML content to be accessed via a URL
path that will set the Content-Type to HTML allowing a requesting browser to
interpret content not properly escaped to prevent Cross-Site Scripting (XSS).
Metrics
Affected Vendors & Products
Advisories
    No advisories yet.
Fixes
    Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
        History
                    Tue, 04 Nov 2025 05:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | 
        
        ssvc
         
  | 
Mon, 03 Nov 2025 16:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | IdentityIQ 8.5, IdentityIQ 8.4 and all 8.4 patch levels prior to 8.4p4, IdentityIQ 8.3 and all 8.3 patch levels prior to 8.3p6, and all prior versions allows some IdentityIQ web services that provide non-HTML content to be accessed via a URL path that will set the Content-Type to HTML allowing a requesting browser to interpret content not properly escaped to prevent Cross-Site Scripting (XSS). | |
| Title | Incorrect Content Type Cross-Site Scripting Vulnerability | |
| Weaknesses | CWE-79 | |
| References | 
         | |
| Metrics | 
        
        cvssV3_1
         
  | 
Status: PUBLISHED
Assigner: SailPoint
Published:
Updated: 2025-11-04T04:55:16.187Z
Reserved: 2025-09-11T16:02:56.954Z
Link: CVE-2025-10280
Updated: 2025-11-03T20:50:35.558Z
Status : Received
Published: 2025-11-03T17:15:32.527
Modified: 2025-11-03T17:15:32.527
Link: CVE-2025-10280
No data.
                        OpenCVE Enrichment
                    No data.