📦 Identityiq

by Sailpoint

🔍 What is Identityiq?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-10905

CRITICAL CVSS 10.0 Dec 2, 2024

This vulnerability allows unauthenticated attackers to access sensitive static content within IdentityIQ application directories via HTTP/HTTPS. It affects IdentityIQ versions 8.4 (prior to 8.4p2), 8....

CVE-2024-2227

CRITICAL CVSS 10.0 Mar 22, 2024

This vulnerability allows attackers to access arbitrary files on the application server file system through a path traversal flaw in JavaServer Faces (JSF) 2.2.20. It affects SailPoint IdentityIQ syst...

CVE-2023-32217

CRITICAL CVSS 9.0 Jun 5, 2023

This vulnerability allows authenticated users in SailPoint IdentityIQ to invoke arbitrary Java constructors via unsafe reflection, potentially executing malicious code. It affects IdentityIQ versions ...

CVE-2025-10280

HIGH CVSS 7.1 Nov 3, 2025

This vulnerability allows cross-site scripting (XSS) attacks in SailPoint IdentityIQ when web services return non-HTML content with an incorrect HTML Content-Type header. Attackers can inject maliciou...

CVE-2024-1714

HIGH CVSS 7.1 Feb 21, 2024

This vulnerability in SailPoint IdentityIQ allows authenticated users to request access to entitlements with leading or trailing whitespace in their values, potentially bypassing intended access contr...