← Back

CVE-2024-3317

nvd nist
Published: May 15, 2024Modified: Jun 17, 2026Deferred

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Exploitability: 2.8 / Impact: 3.6
Source: psirt@sailpoint.com (Secondary)

Description

An improper access control was identified in the Identity Security Cloud (ISC) message server API that allowed an authenticated user to exfiltrate job processing metadata (opaque messageIDs, work queue depth and counts) for other tenants.

References (2)

Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.