CVE-2024-2228Improper Privilege Management in Identityiq

Severity
8.8HIGHNVD
CNA7.1
EPSS
0.2%
top 56.60%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 22

Description

This vulnerability allows an authenticated user to perform a Lifecycle Manager flow or other QuickLink for a target user outside of the defined QuickLink Population.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages2 packages

CVEListV5sailpoint/identityiq8.18.1p7+3

🔴Vulnerability Details

2
CVEList
IdentityIQ Authorization of QuickLink Target Identities Vulnerability2024-03-22
GHSA
GHSA-wv97-q48c-w5m2: This vulnerability allows an authenticated user to perform a Lifecycle Manager flow or other QuickLink for a target user outside of the defined QuickL2024-03-22
CVE-2024-2228 — Improper Privilege Management | cvebase