CVE-2024-10905

EUVD-2024-33546
IdentityIQ 8.4 and all 8.4 patch levels prior to 8.4p2, IdentityIQ 8.3 and all 8.3 patch levels prior to 8.3p5, IdentityIQ 8.2 and all 8.2 patch levels prior to 8.2p8, and all prior versions allow HTTP/HTTPS access to static content in the IdentityIQ application directory that should be protected.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
10 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
SailPointCNA
10 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 75%
Affected Products (NVD)
VendorProductVersion
sailpointidentityiq
8.2p8 <
𝑥
< 8.2p8
sailpointidentityiq
8.3p5 <
𝑥
< 8.3p5
sailpointidentityiq
8.4p2 <
𝑥
< 8.4p2
sailpointidentityiq
𝑥
< 8.2
sailpointidentityiq
8.2
sailpointidentityiq
8.2:patch1
sailpointidentityiq
8.2:patch2
sailpointidentityiq
8.2:patch4
sailpointidentityiq
8.2:patch5
sailpointidentityiq
8.2:patch7
sailpointidentityiq
8.3
sailpointidentityiq
8.3:patch1
sailpointidentityiq
8.3:patch2
sailpointidentityiq
8.3:patch4
sailpointidentityiq
8.4
sailpointidentityiq
8.4:patch1
𝑥
= Vulnerable software versions