Whitespace Issues in IdentityIQ Lifecycle Manager
CVE-2024-1714
7.1HIGH
What is CVE-2024-1714?
A vulnerability in SailPoint IdentityIQ Lifecycle Manager has been identified where authenticated users may exploit an access request feature. This occurs when entitlements containing leading or trailing whitespace are requested, potentially allowing unauthorized access or faulty entitlement processing. The issue signifies the importance of proper input validation to mitigate risks associated with access requests.
Affected Version(s)
IdentityIQ 8.2 < 8.2p7
IdentityIQ 8.3 < 8.3p4
IdentityIQ 8.4 < 8.4p1
References
CVSS V3.1
Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved