← Back

CVE-2023-32217

nvd nist
Published: Jun 5, 2023Modified: Feb 25, 2026

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD

Description

IdentityIQ 8.3 and all 8.3 patch levels prior to 8.3p3, IdentityIQ 8.2 and all 8.2 patch levels prior to 8.2p6, IdentityIQ 8.1 and all 8.1 patch levels prior to 8.1p7, IdentityIQ 8.0 and all 8.0 patch levels prior to 8.0p6 allow an authenticated user to invoke a Java constructor with no arguments or a Java constructor with a single Map argument in any Java class available in the IdentityIQ application classpath.

Affected (17)

1 product
Identityiq
Configuration A
17 vulnerable
Vulnerable SoftwareAffected Versions
Sailpoint
Version 8.0
Version 8.0 patch1
Version 8.0 patch2
Version 8.0 patch3
Version 8.0 patch4
Version 8.1
Version 8.1 patch1
Version 8.1 patch2
Version 8.1 patch3
Version 8.1 patch4
Version 8.1 patch5
Version 8.2
Version 8.2 patch1
Version 8.2 patch2
Version 8.2 patch4
Version 8.3
Version 8.3 patch1

Timeline

No history available yet.