CVE-2024-3317: SailPoint Identity Security Cloud Improper Access Control
An improper access control was identified in the Identity Security Cloud (ISC) message server API that allowed an authenticated user to exfiltrate job processing metadata (opaque messageIDs, work queue depth and counts) for other tenants.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-3317?
CVE-2024-3317 has been rated as a medium severity vulnerability due to the risk of data exfiltration.
How do I fix CVE-2024-3317?
To fix CVE-2024-3317, ensure that access controls are properly configured for the Identity Security Cloud message server API.
Who is affected by CVE-2024-3317?
Organizations using the SailPoint Identity Security Cloud are affected by CVE-2024-3317.
What type of information can be exfiltrated in CVE-2024-3317?
CVE-2024-3317 allows an authenticated user to exfiltrate job processing metadata, including opaque messageIDs and work queue counts.
Is CVE-2024-3317 a zero-day vulnerability?
CVE-2024-3317 is not classified as a zero-day vulnerability but it does pose significant risks to data security.