← Back to browse · API

CVE-2024-10905

Severity
CRITICAL
CVSS
10.0
EPSS
0.00954
Risk score
40.33
CISA KEV
No
PoC
No
Published
2024-12-02
Modified
2025-01-06
First seen
2026-08-07
Aliases
EUVD-2024-33546, GHSA-9JCJ-C3PX-4JC5
Products
SailPoint Technologies:IdentityIQ 8.2 <8.2p8, SailPoint Technologies:IdentityIQ 8.3 <8.3p5, SailPoint Technologies:IdentityIQ 8.4 <8.4p2
Sources
euvd EUVD-2024-33546

Description

IdentityIQ 8.4 and all 8.4 patch levels prior to 8.4p2, IdentityIQ 8.3 and all 8.3 patch levels prior to 8.3p5, IdentityIQ 8.2 and all 8.2 patch levels prior to 8.2p8, and all prior versions allow HTTP/HTTPS access to static content in the IdentityIQ application directory that should be protected.

References