Sailpoint Identityiq vulnerabilities
10 known vulnerabilities affecting sailpoint/identityiq.
Total CVEs
10
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH6MEDIUM3
Vulnerabilities
Page 1 of 1
CVE-2020-6950P3MEDIUMCVSS 6.5PoC≥ 8.1, < 8.1p7≥ 8.2, < 8.2p7+2 more2021-06-02
CVE-2020-6950 [MEDIUM] CWE-22 CVE-2020-6950: Directory traversal in Eclipse Mojarra before 2.3.14 allows attackers to read arbitrary files via th
Directory traversal in Eclipse Mojarra before 2.3.14 allows attackers to read arbitrary files via the loc parameter or con parameter.
nvd
CVE-2024-10905P3CRITICALCVSS 9.8fixed in 8.2v8.2+2 more2024-12-02
CVE-2024-10905 [CRITICAL] CWE-66 CVE-2024-10905: IdentityIQ 8.4 and all 8.4 patch levels prior to 8.4p2, IdentityIQ 8.3 and all 8.3 patch levels prio
IdentityIQ 8.4 and all 8.4 patch levels prior to 8.4p2, IdentityIQ 8.3 and all 8.3 patch levels prior to 8.3p5, IdentityIQ 8.2 and all 8.2 patch levels prior to 8.2p8, and all prior versions allow HTTP/HTTPS access to static content in the IdentityIQ application directory that should be protected.
nvd
CVE-2024-2228P3HIGHCVSS 8.8fixed in 8.1v8.1+7 more2024-03-22
CVE-2024-2228 [HIGH] CWE-269 CVE-2024-2228: This vulnerability allows an authenticated user to perform a Lifecycle Manager flow or other QuickLi
This vulnerability allows an authenticated user to perform a Lifecycle Manager flow or other QuickLink for a target user outside of the defined QuickLink Population.
nvd
CVE-2023-32217P3HIGHCVSS 8.8v8.0v8.1+6 more2023-06-05
CVE-2023-32217 [HIGH] CWE-470 CVE-2023-32217: IdentityIQ 8.3 and all 8.3 patch levels prior to 8.3p3, IdentityIQ 8.2 and all 8.2 patch levels prio
IdentityIQ 8.3 and all 8.3 patch levels prior to 8.3p3, IdentityIQ 8.2 and all 8.2 patch levels prior to 8.2p6, IdentityIQ 8.1 and all 8.1 patch levels prior to 8.1p7, IdentityIQ 8.0 and all 8.0 patch levels prior to 8.0p6 allow an authenticated user to invoke a Java constructor with no arguments or a Java constructor with a single Map argument in any
nvd
CVE-2026-5712P3HIGHCVSS 8.8fixed in 8.3v8.3+2 more2026-04-29
CVE-2026-5712 [HIGH] CWE-863 CVE-2026-5712: This vulnerability impacts all versions of IdentityIQ and allows an authenticated identity that is t
This vulnerability impacts all versions of IdentityIQ and allows an authenticated identity that is the requestor or assignee of a work item to edit the definition of a role without having an assigned capability that would allow role editing.
nvd
CVE-2022-46835P3HIGHCVSS 7.5v8.0v8.1+2 more2023-01-31
CVE-2022-46835 [HIGH] CVE-2022-46835: IdentityIQ 8.3 and all 8.3 patch levels prior to 8.3p2, IdentityIQ 8.2 and all 8.2 patch levels prio
IdentityIQ 8.3 and all 8.3 patch levels prior to 8.3p2, IdentityIQ 8.2 and all 8.2 patch levels prior to 8.2p5, IdentityIQ 8.1 and all 8.1 patch levels prior to 8.1p7, IdentityIQ 8.0 and all 8.0 patch levels prior to 8.0p6 allow access to arbitrary files in the application server filesystem due to a path traversal vulnerability in JavaServer Faces (JSF) 2.2.2
nvd
CVE-2024-2227P3HIGHCVSS 7.5fixed in 8.1v8.1+3 more2024-03-22
CVE-2024-2227 [HIGH] CVE-2024-2227: This vulnerability allows access to arbitrary files in the application server file system due to a p
This vulnerability allows access to arbitrary files in the application server file system due to a path traversal vulnerability in JavaServer Faces (JSF) 2.2.20 documented in CVE-2020-6950. The remediation for this vulnerability contained in this security fix provides additional changes to the remediation announced in May 2021 tracked by ETN IIQSAW-3585 and Jan
nvd
CVE-2022-45435P3MEDIUMCVSS 6.5fixed in 8.0v8.0+7 more2023-01-31
CVE-2022-45435 [MEDIUM] CWE-863 CVE-2022-45435: IdentityIQ 8.3 and all 8.3 patch levels prior to 8.3p2, IdentityIQ 8.2 and all 8.2 patch levels prio
IdentityIQ 8.3 and all 8.3 patch levels prior to 8.3p2, IdentityIQ 8.2 and all 8.2 patch levels prior to 8.2p5, IdentityIQ 8.1 and all 8.1 patch levels prior to 8.1p7, IdentityIQ 8.0 and all 8.0 patch levels prior to 8.0p6, and all prior versions allow authenticated users assigned the Identity Administrator capability or any custom capability that c
nvd
CVE-2024-1714P4HIGHCVSS 7.1v8.1v8.2+5 more2024-02-21
CVE-2024-1714 [HIGH] CWE-20 CVE-2024-1714: An issue exists in all supported versions of IdentityIQ Lifecycle Manager that can result if an enti
An issue exists in all supported versions of IdentityIQ Lifecycle Manager that can result if an entitlement with a value containing leading or trailing whitespace is requested by an authenticated user in an access request.
nvd
CVE-2025-10280P4MEDIUMCVSS 6.1fixed in 8.3v8.3+2 more2025-11-03
CVE-2025-10280 [MEDIUM] CWE-79 CVE-2025-10280: IdentityIQ 8.5, IdentityIQ 8.4 and all 8.4 patch levels prior to 8.4p4, IdentityIQ 8.3 and all 8.3 p
IdentityIQ
8.5, IdentityIQ 8.4 and all 8.4 patch levels prior to 8.4p4, IdentityIQ 8.3 and
all 8.3 patch levels including 8.3p5, and all prior versions allows some
IdentityIQ web services that provide non-HTML content to be accessed via a URL
path that will set the Content-Type to HTML allowing a requesting browser to
interpret content not properly e
nvd