CVE-2024-10905: IdentityIQ Improper Access Control VulnerabilityIdentityIQ Improper Access Control Vulnerability
IdentityIQ 8.4 and all 8.4 patch levels prior to 8.4p2, IdentityIQ 8.3 and all 8.3 patch levels prior to 8.3p5, IdentityIQ 8.2 and all 8.2 patch levels prior to 8.2p8, and all prior versions allow HTTP/HTTPS access to static content in the IdentityIQ application directory that should be protected.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-10905?
CVE-2024-10905 has been classified with a high severity level due to the improper access control allowing unauthorized access to static content.
How do I fix CVE-2024-10905?
To fix CVE-2024-10905, upgrade to IdentityIQ version 8.4p2 or later, 8.3p5 or later, or 8.2p8 or later.
What versions are affected by CVE-2024-10905?
CVE-2024-10905 affects SailPoint IdentityIQ versions 8.4 and earlier patch levels, 8.3 and earlier patch levels, and 8.2 and earlier patch levels.
What type of vulnerability is CVE-2024-10905?
CVE-2024-10905 is characterized as an improper access control vulnerability within the IdentityIQ application.
What are the risks associated with CVE-2024-10905?
The risks associated with CVE-2024-10905 include potential unauthorized access to sensitive static content within the IdentityIQ application.