CVE-2023-32217
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
05/06/2023
Last modified:
12/06/2023
Description
IdentityIQ 8.3 and all 8.3 patch levels prior to 8.3p3, IdentityIQ 8.2 and all 8.2 patch levels prior to 8.2p6, IdentityIQ 8.1 and all 8.1 patch levels prior to 8.1p7, IdentityIQ 8.0 and all 8.0 patch levels prior to 8.0p6 allow an authenticated user to invoke a Java constructor with no arguments or a Java constructor with a single Map argument in any Java class available in the IdentityIQ application classpath.<br />
<br />
Impact
Base Score 3.x
8.80
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:sailpoint:identityiq:8.0:-:*:*:*:*:*:* | ||
| cpe:2.3:a:sailpoint:identityiq:8.0:patch1:*:*:*:*:*:* | ||
| cpe:2.3:a:sailpoint:identityiq:8.0:patch2:*:*:*:*:*:* | ||
| cpe:2.3:a:sailpoint:identityiq:8.0:patch3:*:*:*:*:*:* | ||
| cpe:2.3:a:sailpoint:identityiq:8.0:patch4:*:*:*:*:*:* | ||
| cpe:2.3:a:sailpoint:identityiq:8.1:-:*:*:*:*:*:* | ||
| cpe:2.3:a:sailpoint:identityiq:8.1:patch1:*:*:*:*:*:* | ||
| cpe:2.3:a:sailpoint:identityiq:8.1:patch2:*:*:*:*:*:* | ||
| cpe:2.3:a:sailpoint:identityiq:8.1:patch3:*:*:*:*:*:* | ||
| cpe:2.3:a:sailpoint:identityiq:8.1:patch4:*:*:*:*:*:* | ||
| cpe:2.3:a:sailpoint:identityiq:8.1:patch5:*:*:*:*:*:* | ||
| cpe:2.3:a:sailpoint:identityiq:8.2:-:*:*:*:*:*:* | ||
| cpe:2.3:a:sailpoint:identityiq:8.2:patch1:*:*:*:*:*:* | ||
| cpe:2.3:a:sailpoint:identityiq:8.2:patch2:*:*:*:*:*:* | ||
| cpe:2.3:a:sailpoint:identityiq:8.2:patch4:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



