CVE-2024-2227
EUVD-2024-2718322.03.2024, 16:15
This vulnerability allows access to arbitrary files in the application server file system due to a path traversal vulnerability in JavaServer Faces (JSF) 2.2.20 documented in CVE-2020-6950. The remediation for this vulnerability contained in this security fix provides additional changes to the remediation announced in May 2021 tracked by ETN IIQSAW-3585 and January 2024 tracked by IIQFW-336. This vulnerability in IdentityIQ is assigned CVE-2024-2227.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| sailpoint | identityiq | 𝑥 < 8.1 |
| sailpoint | identityiq | 8.1:patch1 |
| sailpoint | identityiq | 8.1:patch2 |
| sailpoint | identityiq | 8.1:patch3 |
| sailpoint | identityiq | 8.1:patch4 |
| sailpoint | identityiq | 8.1:patch5 |
| sailpoint | identityiq | 8.1:patch6 |
| sailpoint | identityiq | 8.2 |
| sailpoint | identityiq | 8.2:patch1 |
| sailpoint | identityiq | 8.2:patch2 |
| sailpoint | identityiq | 8.2:patch4 |
| sailpoint | identityiq | 8.2:patch5 |
| sailpoint | identityiq | 8.3 |
| sailpoint | identityiq | 8.3:patch1 |
| sailpoint | identityiq | 8.3:patch2 |
| sailpoint | identityiq | 8.4 |
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| sailpoint | identityiq | 8.1 ≤ 𝑥 < 8.1p7 | ADP |
| sailpoint | identityiq | 8.2 ≤ 𝑥 < 8.2p7 | ADP |
| sailpoint | identityiq | 8.3 ≤ 𝑥 < 8.3p4 | ADP |
| sailpoint | identityiq | 8.4 ≤ 𝑥 < 8.4p1 | ADP |