CVE-2024-2228: IdentityIQ Authorization of QuickLink Target Identities Vulnerability
This vulnerability allows an authenticated user to perform a Lifecycle Manager flow or other QuickLink for a target user outside of the defined QuickLink Population.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-2228?
CVE-2024-2228 has a severity rating that may vary based on the specific implementation and context, but it is categorized as a critical vulnerability due to its potential impact on user data integrity.
How do I fix CVE-2024-2228?
To fix CVE-2024-2228, ensure that you apply all relevant patches from SailPoint IdentityIQ as soon as they are available.
Who is affected by CVE-2024-2228?
CVE-2024-2228 affects versions of SailPoint IdentityIQ up to 8.4, specifically those with various patch releases.
What types of attacks can CVE-2024-2228 facilitate?
CVE-2024-2228 can facilitate unauthorized actions by authenticated users, allowing them to interact with Lifecycle Manager flows and QuickLinks beyond their intended scope.
Is CVE-2024-2228 exploitable remotely?
CVE-2024-2228 requires an authenticated user, making it primarily an internal threat rather than a remote exploit.