IdentityIQ 8.3 and all 8.3 patch levels prior to 8.3p2, IdentityIQ 8.2 and all 8.2 patch levels prior to 8.2p5, IdentityIQ 8.1 and all 8.1 patch levels prior to 8.1p7, IdentityIQ 8.0 and all 8.0 patch levels prior to 8.0p6 allow access to arbitrary files in the application server filesystem due to a path traversal vulnerability in JavaServer Faces (JSF) 2.2.20 documented in CVE-2020-6950.
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 07:31
Type | Values Removed | Values Added |
---|---|---|
References | () https://www.sailpoint.com/security-advisories/sailpoint-identityiq-file-traversal-vulnerability-cve-2022-46835/ - Vendor Advisory | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.8 |
Information
Published : 2023-01-31 15:15
Updated : 2024-11-21 07:31
NVD link : CVE-2022-46835
Mitre link : CVE-2022-46835
CVE.ORG link : CVE-2022-46835
JSON object : View
Products Affected
sailpoint
- identityiq
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')