CVE-2024-10905

Published Dec 2, 2024

Last updated 3 months ago

Overview

Description
IdentityIQ 8.4 and all 8.4 patch levels prior to 8.4p2, IdentityIQ 8.3 and all 8.3 patch levels prior to 8.3p5, IdentityIQ 8.2 and all 8.2 patch levels prior to 8.2p8, and all prior versions allow HTTP/HTTPS access to static content in the IdentityIQ application directory that should be protected.
Source
psirt@sailpoint.com
NVD status
Awaiting Analysis

Risk scores

CVSS 3.1

Type
Secondary
Base score
10
Impact score
6
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Severity
CRITICAL

Weaknesses

psirt@sailpoint.com
CWE-66

Social media

Hype score
Not currently trending
  1. Warning: @SailPoint patched a critical vulnerability, CVE-2024-10905 (CVSS 10), in #IdentityIQ. Exploitation could lead to data exposure or modification. More information in our advisory https://t.co/dp8AHsqS7q. Time to #Patch #Patch #Patch

    @CCBalert

    9 Dec 2024

    240 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. 🚨Critical Vulnerability in SailPoint IdentityIQ Exposes Sensitive Files! 🚨 WIRE TOR - The Ethical Hacking Services 🔥 Overview: A newly discovered critical vulnerability (CVE-2024-10905) in SailPoint IdentityIQ has shaken the cybersecurity world. #hacking https://t.co/DMSOfnQ

    @WireTor

    8 Dec 2024

    36 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. 🚨 Critical IAM Vulnerability Found 🚨 Sensitive data is at risk! CVSS score: 10 This flaw (CVE-2024-10905) in SailPoint IdentityIQ allows attackers to: - Compromise systems with malware - Access sensitive data What can you do? ✅ Update to version 8.4p2+ https://t.co/aDnOi2z

    @amartya_jha_

    6 Dec 2024

    115 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  4. SailPoint IdentityIQ affected by CVE-2024-10905 #Sailpoint #CVE-2024-10905 https://t.co/BDyifVgmJQ

    @pravin_karthik

    5 Dec 2024

    44 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. Threat Alert: Critical SailPoint IdentityIQ Vulnerability Exposes Files to Unauthorized Access CVE-2024-10905 Severity: ⚠️ Critical Maturity: 💢 Emerging Learn more: https://t.co/67GMceVnYk #CyberSecurity #ThreatIntel #InfoSec

    @fletch_ai

    5 Dec 2024

    42 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. CVE-2024-10905 (CVSS 10): Critical Vulnerability in SailPoint IdentityIQ Exposes Sensitive Data Learn about the critical vulnerability in SailPoint IdentityIQ and its potential impact on organizations. https://t.co/XDnowP4o75

    @the_yellow_fall

    5 Dec 2024

    349 Impressions

    3 Retweets

    10 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  7. Une vulnérabilité critique dans SailPoint IdentityIQ (CVE-2024-10905) expose des fichiers à un accès non autorisé. Sévérité maximale (CVSS 10.0). Analystes Sécurité, restez informés ! #Cybersecurité #Vulnérabilité 👉 https://t.co/Ol3vG7q9Bq

    @CyberAlertFr

    4 Dec 2024

    34 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. Critical CVE-2024-10905 Vulnerability Exposes SailPoint IdentityIQ to Unauthorized Access A recently discovered vulnerability, CVE-2024-10905, poses a serious threat to SailPoint IdentityIQ, potentially allowing unauthorized access to sensitive data. https://t.co/ZWc4gxp8wb

    @MythoByte

    4 Dec 2024

    112 Impressions

    1 Retweet

    2 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. 1/ 🚨 Critical SailPoint IdentityIQ Vulnerability Exposes Files 🚨 A severe flaw (CVE-2024-10905) has been disclosed in SailPoint's IdentityIQ IAM software, allowing unauthorized access to content stored in the app's directory. This vulnerability has a CVSS score of 10.0. https:/

    @cyraxsecurity

    4 Dec 2024

    64 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  10. 🚨 Alert: A critical vulnerability (CVE-2024-10905) in SailPoint's IdentityIQ software exposes sensitive content. CVSS score? A whopping 10.0—maximum severity. Learn more: https://t.co/erSJUu4FXH #infosec

    @TheHackersNews

    4 Dec 2024

    11348 Impressions

    27 Retweets

    51 Likes

    5 Bookmarks

    0 Replies

    1 Quote

  11. 🚨 Alert: A critical vulnerability (CVE-2024-10905) in SailPoint's IdentityIQ software exposes sensitive content. CVSS score? A whopping 10.0—maximum severity. Learnmore: https://t.co/erSJUu4FXH #infosec

    @TheHackersNews

    4 Dec 2024

    353 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  12. CVE-2024-10905 IdentityIQ 8.4 and all 8.4 patch levels prior to 8.4p2, IdentityIQ 8.3 and all 8.3 patch levels prior to 8.3p5, IdentityIQ 8.2 and all 8.2 patch levels prior to 8.2p8… https://t.co/v6ZBfA3cpO

    @CVEnew

    2 Dec 2024

    216 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  13. [CVE-2024-10905: CRITICAL] IdentityIQ versions 8.4, 8.3, and 8.2 and their respective patch levels have a vulnerability allowing HTTP access to sensitive content. Update to stay secure.#cybersecurity,#vulnerability https://t.co/GZl71s4ipO https://t.co/DZFgzfYeMG

    @CveFindCom

    2 Dec 2024

    15 Impressions

    1 Retweet

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes