All 9 CVE vulnerabilities found in IdentityIQ, with AI-generated Chinese analysis, references, and POCs.
Vendor: SailPoint
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-4857 | SailPoint IdentityIQ Debug UI Incorrect Authorization CWE-863 | 8.4 | High | 2026-04-15 |
| CVE-2025-10280 | Incorrect Content Type Cross-Site Scripting Vulnerability CWE-79 | 7.1 | High | 2025-11-03 |
| CVE-2024-10905 | IdentityIQ Improper Access Control VulnerabilityIdentityIQ Improper Access Control Vulnerability CWE-66 | 10.0 | Critical | 2024-12-02 |
| CVE-2024-2228 | IdentityIQ Authorization of QuickLink Target Identities Vulnerability CWE-269 | 7.1 | High | 2024-03-22 |
| CVE-2024-2227 | IdentityIQ JavaServer Faces File Path Traversal Vulnerability CWE-22 | 10.0 | Critical | 2024-03-22 |
| CVE-2024-1714 | Access Request for Entitlement Values with Leading/Trailing Whitespace CWE-20 | 7.1 | High | 2024-02-21 |
| CVE-2023-32217 | SailPoint IdentityIQ Unsafe use of Reflection Vulnerability CWE-470 | 9.0 | Critical | 2023-05-31 |
| CVE-2022-45435 | SailPoint IdentityIQ Access Control Bypass CWE-863 | 6.8 | Medium | 2023-01-31 |
| CVE-2022-46835 | SailPoint IdentityIQ JavaServer File Path Traversal Vulnerability CWE-22 | 8.8 | High | 2023-01-31 |
All 9 known CVE vulnerabilities affecting IdentityIQ with full Chinese analysis, references, and POCs where available.