Critical SailPoint IdentityIQ Vulnerability Exposes Files to Unauthorized Access

Teilen:

A critical security vulnerability has been disclosed in SailPoint’s IdentityIQ identity and access management (IAM) software that allows unauthorized access to content stored within the application directory.

The flaw, tracked as CVE-2024-10905, has a CVSS score of 10.0, indicating maximum severity. It affects IdentityIQ versions 8.2. 8.3, 8.4, and other previous versions.

IdentityIQ “allows HTTP access to static content in the IdentityIQ application directory that should be protected,” according to a description of the flaw on NIST’s National Vulnerability Database (NVD).

The vulnerability has been characterized as a case of improper handling of file names that identify virtual resources (CWE-66), which could be abused to read otherwise inaccessible files.

In an alert of its own, SailPoint said it has “released e-fixes for each impacted and supported version of IdentityIQ.” The exact list of versions impacted by CVE-2024-10905 is mentioned below –

  • 8.4 and all 8.4 patch levels prior to 8.4p2
  • 8.3 and all 8.3 patch levels prior to 8.3p5
  • 8.2 and all 8.2 patch levels prior to 8.2p8, and
  • All prior versions

The Hacker News has reached out to SailPoint for comment prior to the publication of this story and will update the piece if we hear back from the company.

Update

In response to our queries, SailPoint CISO Rex Booth shared following statement with The Hacker News –

As part of our continued commitment to transparency and security, on Monday December 2, SailPoint issued a security advisory for its Identity IQ product which was assigned CVE-2024-10905. A fix has already been released, and we’ve provided customers with guidance on how to apply it.

Publishing CVEs is a voluntary practice across the industry that demonstrates dedication to security and transparency. At SailPoint, we invest in secure development practices and strive to catch vulnerabilities prior to software release, but, as with all software, new vulnerabilities can emerge as attacker tactics and detection capabilities evolve. For this reason, we continually test our products in all stages of the development lifecycle to minimize risk to our customers. Finding and remediating vulnerabilities is a symptom of a mature security program, and a company dedicated to safeguarding the cyber ecosystem.

Quelle

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
4:41 pm, März 27, 2025
Wetter-Symbol 14°C
L: 14° | H: 14°
klarer Himmel
Luftfeuchtigkeit: 64 %
Druck: 1017 mb
Wind: 10 mph WSW
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 6%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 5:46 am
Sonnenuntergang: 6:24 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 9:00 pm
Wetter-Symbol
10° | 14°°C 0 mm 0% 7 mph 80 % 1017 mb 0 mm/h
Tomorrow 9:00 pm
Wetter-Symbol
6° | 13°°C 0.38 mm 38% 13 mph 86 % 1016 mb 0 mm/h
Sa. März 29 9:00 pm
Wetter-Symbol
4° | 13°°C 0 mm 0% 9 mph 78 % 1022 mb 0 mm/h
So. März 30 9:00 pm
Wetter-Symbol
8° | 17°°C 0 mm 0% 11 mph 93 % 1025 mb 0 mm/h
Mo. März 31 9:00 pm
Wetter-Symbol
8° | 15°°C 0 mm 0% 9 mph 79 % 1027 mb 0 mm/h
Today 6:00 pm
Wetter-Symbol
14° | 14°°C 0 mm 0% 7 mph 65 % 1017 mb 0 mm/h
Today 9:00 pm
Wetter-Symbol
10° | 10°°C 0 mm 0% 7 mph 80 % 1017 mb 0 mm/h
Tomorrow 12:00 am
Wetter-Symbol
7° | 7°°C 0 mm 0% 7 mph 85 % 1015 mb 0 mm/h
Tomorrow 3:00 am
Wetter-Symbol
6° | 6°°C 0 mm 0% 8 mph 84 % 1013 mb 0 mm/h
Tomorrow 6:00 am
Wetter-Symbol
9° | 9°°C 0 mm 0% 9 mph 86 % 1012 mb 0 mm/h
Tomorrow 9:00 am
Wetter-Symbol
10° | 10°°C 0.28 mm 28% 9 mph 85 % 1011 mb 0 mm/h
Tomorrow 12:00 pm
Wetter-Symbol
13° | 13°°C 0.38 mm 38% 12 mph 49 % 1012 mb 0 mm/h
Tomorrow 3:00 pm
Wetter-Symbol
12° | 12°°C 0 mm 0% 13 mph 42 % 1012 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€80,815.22
0.18%
Ethereum(ETH)
€1,864.06
-0.52%
Fesseln(USDT)
€0.93
-0.03%
XRP(XRP)
€2.18
-2.60%
Solana(SOL)
€128.25
-1.25%
USDC(USDC)
€0.93
-0.01%
Dogecoin(DOGE)
€0.178316
-2.44%
Shiba Inu(SHIB)
€0.000013
-3.05%
Pepe(PEPE)
€0.000008
-3.00%
Peanut das Eichhörnchen(PNUT)
€0.213778
7.85%
Nach oben scrollen