A serious vulnerability has been identified in the identity and access management (IAM) software “SailPoint IdentityIQ”, which allows unauthorized access to content stored in the application directory.

The vulnerability, listed as CVE-2024-10905, has a CVSS score of 10.0, indicating the maximum severity. It affects versions 8.2, 8.3, 8.4, and all older versions.
Read more: Type Confusion vulnerability in Google Chrome allows remote access
According to the NIST National Vulnerability Database (NVD), the vulnerability “allows access over HTTP to static content in the IdentityIQ application directory, which should normally be protected.”.
The vulnerability is classified as a case of incorrect handling of file names referring to virtual resources (CWE-66). This weakness can be exploited to read files that would normally be inaccessible.

At this time, no further details about the vulnerability have been released, and SailPoint has not issued an official security advisory. The affected versions of IdentityIQ include:
See more: Critical vulnerability in Zabbix network monitoring tool
- Version 8.4 and all patch levels prior to 8.4p2
- Version 8.3 and all patch levels prior to 8.3p5
- Version 8.2 and all patch levels prior to 8.2p8
- All previous versions
Source: thehackernews
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
