← Back

CVE-2024-1714

nvd nist
Published: Feb 21, 2024Modified: Sep 30, 2025

JSON object

Loading...
7.1
Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:L/A:L
Exploitability: 1.3 / Impact: 5.3
Source: psirt@sailpoint.com (Secondary)

Description

An issue exists in all supported versions of IdentityIQ Lifecycle Manager that can result if an entitlement with a value containing leading or trailing whitespace is requested by an authenticated user in an access request.

Affected (14)

1 product
Identityiq
Configuration A
14 vulnerable
Vulnerable SoftwareAffected Versions
Sailpoint
Version 8.1
Version 8.1 patch1
Version 8.1 patch2
Version 8.1 patch3
Version 8.1 patch4
Version 8.1 patch5
Version 8.1 patch6
Version 8.2
Version 8.2 patch1
Version 8.2 patch2
Version 8.2 patch4
Version 8.3
Version 8.3 patch1
Version 8.4

Timeline

No history available yet.