Description
IdentityIQ 8.3 and all 8.3 patch levels prior to 8.3p3, IdentityIQ 8.2 and all 8.2 patch levels prior to 8.2p6, IdentityIQ 8.1 and all 8.1 patch levels prior to 8.1p7, IdentityIQ 8.0 and all 8.0 patch levels prior to 8.0p6 allow an authenticated user to invoke a Java constructor with no arguments or a Java constructor with a single Map argument in any Java class available in the IdentityIQ application classpath.
References (1)
Core 1
Core References
Scores
CVSS v3
9.0
EPSS
0.0063
EPSS Percentile
45.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-470
Status
published
Products (4)
sailpoint/identityiq
8.0 (5 CPE variants)
sailpoint/identityiq
8.1 (6 CPE variants)
sailpoint/identityiq
8.2 (4 CPE variants)
sailpoint/identityiq
8.3 (2 CPE variants)
Published
Jun 05, 2023
Tracked Since
Feb 18, 2026