Unrestricted Access to Target User Data via Lifecycle Manager Flow
CVE-2024-2228
7.1HIGH
What is CVE-2024-2228?
An authentication vulnerability exists in SailPoint Lifecycle Manager that enables an authenticated user to conduct Lifecycle Manager operations or utilize a QuickLink for a designated target user, bypassing the established restrictions of the QuickLink Population. This oversight can potentially allow for unauthorized actions, threatening the integrity of user data and access management systems.
Affected Version(s)
IdentityIQ 8.1 < 8.1p7
IdentityIQ 8.2 < 8.2p7
IdentityIQ 8.3 < 8.3p4