Whitespace Issues in IdentityIQ Lifecycle Manager
CVE-2024-1714

7.1HIGH

Key Information:

Vendor

Sailpoint

Vendor
CVE Published:
21 February 2024

What is CVE-2024-1714?

A vulnerability in SailPoint IdentityIQ Lifecycle Manager has been identified where authenticated users may exploit an access request feature. This occurs when entitlements containing leading or trailing whitespace are requested, potentially allowing unauthorized access or faulty entitlement processing. The issue signifies the importance of proper input validation to mitigate risks associated with access requests.

Affected Version(s)

IdentityIQ 8.2 < 8.2p7

IdentityIQ 8.3 < 8.3p4

IdentityIQ 8.4 < 8.4p1

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2024-1714 : Whitespace Issues in IdentityIQ Lifecycle Manager