CVE-2025-10280

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
03/11/2025
Last modified:
12/11/2025

Description

IdentityIQ<br /> 8.5, IdentityIQ 8.4 and all 8.4 patch levels prior to 8.4p4, IdentityIQ 8.3 and<br /> all 8.3 patch levels including 8.3p5, and all prior versions allows some<br /> IdentityIQ web services that provide non-HTML content to be accessed via a URL<br /> path that will set the Content-Type to HTML allowing a requesting browser to<br /> interpret content not properly escaped to prevent Cross-Site Scripting (XSS).

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:sailpoint:identityiq:*:*:*:*:*:*:*:* 8.3 (excluding)
cpe:2.3:a:sailpoint:identityiq:8.3:-:*:*:*:*:*:*
cpe:2.3:a:sailpoint:identityiq:8.3:patch1:*:*:*:*:*:*
cpe:2.3:a:sailpoint:identityiq:8.3:patch2:*:*:*:*:*:*
cpe:2.3:a:sailpoint:identityiq:8.3:patch4:*:*:*:*:*:*
cpe:2.3:a:sailpoint:identityiq:8.3:patch5:*:*:*:*:*:*
cpe:2.3:a:sailpoint:identityiq:8.4:-:*:*:*:*:*:*
cpe:2.3:a:sailpoint:identityiq:8.4:patch1:*:*:*:*:*:*
cpe:2.3:a:sailpoint:identityiq:8.4:patch2:*:*:*:*:*:*
cpe:2.3:a:sailpoint:identityiq:8.5:-:*:*:*:*:*:*