CVE-2022-45435

IdentityIQ 8.3 and all 8.3 patch levels prior to 8.3p2, IdentityIQ 8.2 and all 8.2 patch levels prior to 8.2p5, IdentityIQ 8.1 and all 8.1 patch levels prior to 8.1p7, IdentityIQ 8.0 and all 8.0 patch levels prior to 8.0p6, and all prior versions allow authenticated users assigned the Identity Administrator capability or any custom capability that contains the SetIdentityForwarding right to modify the work item forwarding configuration for identities other than the ones that should be allowed by Lifecycle Manager Quicklink Population configuration.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:sailpoint:identityiq:*:*:*:*:*:*:*:*
cpe:2.3:a:sailpoint:identityiq:8.0:-:*:*:*:*:*:*
cpe:2.3:a:sailpoint:identityiq:8.0:patch1:*:*:*:*:*:*
cpe:2.3:a:sailpoint:identityiq:8.0:patch2:*:*:*:*:*:*
cpe:2.3:a:sailpoint:identityiq:8.0:patch3:*:*:*:*:*:*
cpe:2.3:a:sailpoint:identityiq:8.0:patch4:*:*:*:*:*:*
cpe:2.3:a:sailpoint:identityiq:8.0:patch5:*:*:*:*:*:*
cpe:2.3:a:sailpoint:identityiq:8.1:-:*:*:*:*:*:*
cpe:2.3:a:sailpoint:identityiq:8.1:patch1:*:*:*:*:*:*
cpe:2.3:a:sailpoint:identityiq:8.1:patch2:*:*:*:*:*:*
cpe:2.3:a:sailpoint:identityiq:8.1:patch3:*:*:*:*:*:*
cpe:2.3:a:sailpoint:identityiq:8.1:patch4:*:*:*:*:*:*
cpe:2.3:a:sailpoint:identityiq:8.1:patch5:*:*:*:*:*:*
cpe:2.3:a:sailpoint:identityiq:8.1:patch6:*:*:*:*:*:*
cpe:2.3:a:sailpoint:identityiq:8.2:-:*:*:*:*:*:*
cpe:2.3:a:sailpoint:identityiq:8.2:patch1:*:*:*:*:*:*
cpe:2.3:a:sailpoint:identityiq:8.2:patch2:*:*:*:*:*:*
cpe:2.3:a:sailpoint:identityiq:8.2:patch4:*:*:*:*:*:*
cpe:2.3:a:sailpoint:identityiq:8.3:-:*:*:*:*:*:*
cpe:2.3:a:sailpoint:identityiq:8.3:patch1:*:*:*:*:*:*

History

08 Feb 2023, 02:18

Type Values Removed Values Added
CPE cpe:2.3:a:sailpoint:identityiq:8.1:patch6:*:*:*:*:*:*
cpe:2.3:a:sailpoint:identityiq:8.1:patch1:*:*:*:*:*:*
cpe:2.3:a:sailpoint:identityiq:*:*:*:*:*:*:*:*
cpe:2.3:a:sailpoint:identityiq:8.0:patch2:*:*:*:*:*:*
cpe:2.3:a:sailpoint:identityiq:8.1:patch2:*:*:*:*:*:*
cpe:2.3:a:sailpoint:identityiq:8.3:patch1:*:*:*:*:*:*
cpe:2.3:a:sailpoint:identityiq:8.0:patch5:*:*:*:*:*:*
cpe:2.3:a:sailpoint:identityiq:8.2:-:*:*:*:*:*:*
cpe:2.3:a:sailpoint:identityiq:8.0:patch1:*:*:*:*:*:*
cpe:2.3:a:sailpoint:identityiq:8.2:patch1:*:*:*:*:*:*
cpe:2.3:a:sailpoint:identityiq:8.0:patch3:*:*:*:*:*:*
cpe:2.3:a:sailpoint:identityiq:8.0:-:*:*:*:*:*:*
cpe:2.3:a:sailpoint:identityiq:8.0:patch4:*:*:*:*:*:*
cpe:2.3:a:sailpoint:identityiq:8.2:patch2:*:*:*:*:*:*
cpe:2.3:a:sailpoint:identityiq:8.2:patch4:*:*:*:*:*:*
cpe:2.3:a:sailpoint:identityiq:8.3:-:*:*:*:*:*:*
cpe:2.3:a:sailpoint:identityiq:8.1:patch5:*:*:*:*:*:*
cpe:2.3:a:sailpoint:identityiq:8.1:patch3:*:*:*:*:*:*
cpe:2.3:a:sailpoint:identityiq:8.1:patch4:*:*:*:*:*:*
cpe:2.3:a:sailpoint:identityiq:8.1:-:*:*:*:*:*:*
First Time Sailpoint
Sailpoint identityiq
CWE CWE-863
References (MISC) https://www.sailpoint.com/security-advisories/sailpoint-identityiq-identity-forwarding-vulnerability-cve-2022-45435/ - (MISC) https://www.sailpoint.com/security-advisories/sailpoint-identityiq-identity-forwarding-vulnerability-cve-2022-45435/ - Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5

31 Jan 2023, 15:39

Type Values Removed Values Added
New CVE

Information

Published : 2023-01-31 15:15

Updated : 2023-12-10 14:48


NVD link : CVE-2022-45435

Mitre link : CVE-2022-45435

CVE.ORG link : CVE-2022-45435


JSON object : View

Products Affected

sailpoint

  • identityiq
CWE
CWE-863

Incorrect Authorization