← Back

CVE-2024-10905

nvd nist
Published: Dec 2, 2024Modified: Jun 17, 2026

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

IdentityIQ 8.4 and all 8.4 patch levels prior to 8.4p2, IdentityIQ 8.3 and all 8.3 patch levels prior to 8.3p5, IdentityIQ 8.2 and all 8.2 patch levels prior to 8.2p8, and all prior versions allow HTTP/HTTPS access to static content in the IdentityIQ application directory that should be protected.

Affected (13)

1 product
Identityiq
Configuration A
13 vulnerable
Vulnerable SoftwareAffected Versions
Sailpoint
Before 8.2
Version 8.2
Version 8.2 patch1
Version 8.2 patch2
Version 8.2 patch4
Version 8.2 patch5
Version 8.2 patch7
Version 8.3
Version 8.3 patch1
Version 8.3 patch2
Version 8.3 patch4
Version 8.4
Version 8.4 patch1

Timeline

No history available yet.