Insecure Direct Object Reference in One Identity Identity Manager
CVE-2024-56404

9.9CRITICAL

Key Information:

Vendor
CVE Published:
24 January 2025

What is CVE-2024-56404?

An insecure direct object reference (IDOR) vulnerability exists in One Identity Identity Manager 9.x before version 9.3. This vulnerability poses a risk of privilege escalation within on-premise installations, potentially allowing unauthorized users access to sensitive operations that should be restricted.

Affected Version(s)

Identity Manager 9.0.0 < 9.3

References

CVSS V3.1

Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.