SailPoint IdentityIQ Access Control Bypass
CVE-2022-45435

6.8MEDIUM

Key Information:

Vendor

Sailpoint

Vendor
CVE Published:
31 January 2023

What is CVE-2022-45435?

IdentityIQ 8.3 and all 8.3 patch levels prior to 8.3p2, IdentityIQ 8.2 and all 8.2 patch levels prior to 8.2p5, IdentityIQ 8.1 and all 8.1 patch levels prior to 8.1p7, IdentityIQ 8.0 and all 8.0 patch levels prior to 8.0p6, and all prior versions allow authenticated users assigned the Identity Administrator capability or any custom capability that contains the SetIdentityForwarding right to modify the work item forwarding configuration for identities other than the ones that should be allowed by Lifecycle Manager Quicklink Population configuration.

Affected Version(s)

IdentityIQ 8.3 <= 8.3p1

IdentityIQ 8.2 <= 8.2p4

IdentityIQ 8.1 <= 8.1p6

References

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Elisia Chessel,Klarna AB
.