CVE-2024-2228
Severity CVSS v4.0:
Pending analysis
Type:
CWE-269
Improper Privilege Management
Publication date:
22/03/2024
Last modified:
12/11/2025
Description
This vulnerability allows an authenticated user to perform a Lifecycle Manager flow or other QuickLink for a target user outside of the defined QuickLink Population.
Impact
Base Score 3.x
7.10
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:sailpoint:identityiq:*:*:*:*:*:*:*:* | 8.1 (excluding) | |
| cpe:2.3:a:sailpoint:identityiq:8.1:patch1:*:*:*:*:*:* | ||
| cpe:2.3:a:sailpoint:identityiq:8.1:patch2:*:*:*:*:*:* | ||
| cpe:2.3:a:sailpoint:identityiq:8.1:patch3:*:*:*:*:*:* | ||
| cpe:2.3:a:sailpoint:identityiq:8.1:patch4:*:*:*:*:*:* | ||
| cpe:2.3:a:sailpoint:identityiq:8.1:patch5:*:*:*:*:*:* | ||
| cpe:2.3:a:sailpoint:identityiq:8.1:patch6:*:*:*:*:*:* | ||
| cpe:2.3:a:sailpoint:identityiq:8.2:-:*:*:*:*:*:* | ||
| cpe:2.3:a:sailpoint:identityiq:8.2:patch1:*:*:*:*:*:* | ||
| cpe:2.3:a:sailpoint:identityiq:8.2:patch2:*:*:*:*:*:* | ||
| cpe:2.3:a:sailpoint:identityiq:8.2:patch4:*:*:*:*:*:* | ||
| cpe:2.3:a:sailpoint:identityiq:8.2:patch5:*:*:*:*:*:* | ||
| cpe:2.3:a:sailpoint:identityiq:8.3:-:*:*:*:*:*:* | ||
| cpe:2.3:a:sailpoint:identityiq:8.3:patch1:*:*:*:*:*:* | ||
| cpe:2.3:a:sailpoint:identityiq:8.3:patch2:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



