SailPoint IdentityIQ Improper Form Validation Vulnerability
28Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 9.6epss 0.2%
exploitation probability
0.2%top 92% of all CVEs
observed exploitation
nono source reports it
This vulnerability
impacts all versions of IdentityIQ and allows an unauthenticated user remote
code execution on the IdentityIQ server due to improper input validation of
submitted web service API content.
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Affected products
SailPoint Technologies · IdentityIQ