CVE-2024-3319: Security implication in SailPoint Identity Security Cloud IdentityProfile API Endpoints
An issue was identified in the Identity Security Cloud (ISC) Transform preview and IdentityProfile preview API endpoints that allowed an authenticated administrator to execute user-defined templates as part of attribute transforms which could allow remote code execution on the host.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-3319?
CVE-2024-3319 has been classified as a critical vulnerability due to the potential for remote code execution.
How do I fix CVE-2024-3319?
To fix CVE-2024-3319, ensure that you update to the latest version of SailPoint Identity Security Cloud that contains the necessary patches.
Who is affected by CVE-2024-3319?
CVE-2024-3319 affects organizations using the SailPoint Identity Security Cloud, specifically those utilizing the Transform preview and IdentityProfile preview API endpoints.
What type of vulnerability is CVE-2024-3319?
CVE-2024-3319 is a remote code execution vulnerability caused by allowing user-defined templates in attribute transforms.
Is CVE-2024-3319 exploitable without authentication?
No, CVE-2024-3319 requires an authenticated administrator to exploit the vulnerability.