Cross-Site Scripting Vulnerability in SailPoint IdentityIQ
CVE-2025-10280 
7.1HIGH
What is CVE-2025-10280?
SailPoint's IdentityIQ versions prior to 8.4p4 and 8.3p6, as well as all earlier releases, contain a Cross-Site Scripting vulnerability. This flaw allows certain IdentityIQ web services, designed to provide non-HTML content, to be accessed through URL paths that incorrectly set the Content-Type to HTML. As a result, requesting browsers can misinterpret unescaped content, leading to potential XSS attacks. It is essential for users of affected versions to apply the necessary patches promptly to mitigate this risk.
Affected Version(s)
IdentityIQ 8.5
IdentityIQ 8.5
IdentityIQ 8.4 < 8.4p4
