CVE-2025-10280
Severity CVSS v4.0:
Pending analysis
Type:
CWE-79
Cross-Site Scripting (XSS)
Publication date:
03/11/2025
Last modified:
12/11/2025
Description
IdentityIQ<br />
8.5, IdentityIQ 8.4 and all 8.4 patch levels prior to 8.4p4, IdentityIQ 8.3 and<br />
all 8.3 patch levels including 8.3p5, and all prior versions allows some<br />
IdentityIQ web services that provide non-HTML content to be accessed via a URL<br />
path that will set the Content-Type to HTML allowing a requesting browser to<br />
interpret content not properly escaped to prevent Cross-Site Scripting (XSS).
Impact
Base Score 3.x
7.10
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:sailpoint:identityiq:*:*:*:*:*:*:*:* | 8.3 (excluding) | |
| cpe:2.3:a:sailpoint:identityiq:8.3:-:*:*:*:*:*:* | ||
| cpe:2.3:a:sailpoint:identityiq:8.3:patch1:*:*:*:*:*:* | ||
| cpe:2.3:a:sailpoint:identityiq:8.3:patch2:*:*:*:*:*:* | ||
| cpe:2.3:a:sailpoint:identityiq:8.3:patch4:*:*:*:*:*:* | ||
| cpe:2.3:a:sailpoint:identityiq:8.3:patch5:*:*:*:*:*:* | ||
| cpe:2.3:a:sailpoint:identityiq:8.4:-:*:*:*:*:*:* | ||
| cpe:2.3:a:sailpoint:identityiq:8.4:patch1:*:*:*:*:*:* | ||
| cpe:2.3:a:sailpoint:identityiq:8.4:patch2:*:*:*:*:*:* | ||
| cpe:2.3:a:sailpoint:identityiq:8.5:-:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



