Lucene search

K
cvelistSailPointCVELIST:CVE-2022-45435
HistoryJan 31, 2023 - 12:00 a.m.

CVE-2022-45435 SailPoint IdentityIQ Access Control Bypass

2023-01-3100:00:00
CWE-863
SailPoint
www.cve.org
cve-2022-45435
sailpoint identityiq
access control bypass
work item forwarding configuration
lifecycle manager quicklink population configuration

CVSS3

6.8

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N

AI Score

6.7

Confidence

High

EPSS

0.001

Percentile

21.0%

IdentityIQ 8.3 and all 8.3 patch levels prior to 8.3p2, IdentityIQ 8.2 and all 8.2 patch levels prior to 8.2p5, IdentityIQ 8.1 and all 8.1 patch levels prior to 8.1p7, IdentityIQ 8.0 and all 8.0 patch levels prior to 8.0p6, and all prior versions allow authenticated users assigned the Identity Administrator capability or any custom capability that contains the SetIdentityForwarding right to modify the work item forwarding configuration for identities other than the ones that should be allowed by Lifecycle Manager Quicklink Population configuration.

CNA Affected

[
  {
    "vendor": "SailPoint",
    "product": "IdentityIQ",
    "versions": [
      {
        "version": "8.3",
        "status": "affected",
        "lessThanOrEqual": "8.3p1",
        "versionType": "custom"
      },
      {
        "version": "8.2",
        "status": "affected",
        "lessThanOrEqual": "8.2p4",
        "versionType": "custom"
      },
      {
        "version": "8.1",
        "status": "affected",
        "lessThanOrEqual": "8.1p6",
        "versionType": "custom"
      },
      {
        "version": "8.0",
        "status": "affected",
        "lessThanOrEqual": "8.0p5",
        "versionType": "custom"
      }
    ]
  }
]

CVSS3

6.8

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N

AI Score

6.7

Confidence

High

EPSS

0.001

Percentile

21.0%

Related for CVELIST:CVE-2022-45435