Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2023-32217: SailPoint IdentityIQ Unsafe use of Reflection Vulnerability- CVE-2023-32217

IdentityIQ 8.3 and all 8.3 patch levels prior to 8.3p3, IdentityIQ 8.2 and all 8.2 patch levels prior to 8.2p6, IdentityIQ 8.1 and all 8.1 patch levels prior to 8.1p7, IdentityIQ 8.0 and all 8.0 patch levels prior to 8.0p6 allow an authenticated user to invoke a Java constructor with no arguments or a Java constructor with a single Map argument in any Java class available in the IdentityIQ application classpath.

CVE
#vulnerability#java#auth

Description

This vulnerability allows an authenticated user to invoke a Java constructor with no arguments or a Java
constructor with a single Map argument in any Java class available in the IdentityIQ application
classpath.

Affected product and versions

IdentityIQ 8.3 and all 8.3 patch levels prior to 8.3p2

IdentityIQ 8.2 and all 8.2 patch levels prior to 8.2p5

IdentityIQ 8.1 and all 8.1 patch levels prior to 8.1p6

IdentityIQ 8.0 and all 8.0 patch levels prior to 8.0p5

Resolution

SailPoint has released e-fixes for each impacted and supported version of IdentityIQ. Future patch levels
will include the fixes once they become available.

CVE details

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda