CVE-2022-46835

HIGH

IdentityIQ <8.3p2, <8.2p5, <8.1p7, <8.0p6 - Path Traversal

Title source: llm
STIX 2.1

Description

IdentityIQ 8.3 and all 8.3 patch levels prior to 8.3p2, IdentityIQ 8.2 and all 8.2 patch levels prior to 8.2p5, IdentityIQ 8.1 and all 8.1 patch levels prior to 8.1p7, IdentityIQ 8.0 and all 8.0 patch levels prior to 8.0p6 allow access to arbitrary files in the application server filesystem due to a path traversal vulnerability in JavaServer Faces (JSF) 2.2.20 documented in CVE-2020-6950.

Scores

CVSS v3 8.8
EPSS 0.0094
EPSS Percentile 56.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-22
Status published
Products (4)
sailpoint/identityiq 8.0 (6 CPE variants)
sailpoint/identityiq 8.1 (7 CPE variants)
sailpoint/identityiq 8.2 (4 CPE variants)
sailpoint/identityiq 8.3 (2 CPE variants)
Published Jan 31, 2023
Tracked Since Feb 18, 2026