CVE-2024-1714

An issue exists in all supported versions of IdentityIQ Lifecycle Manager that can result if an entitlement with a value containing leading or trailing whitespace is requested by an authenticated user in an access request.
Configurations

No configuration.

History

21 Nov 2024, 08:51

Type Values Removed Values Added
References () https://www.sailpoint.com/security-advisories/sailpoint-identityiq-access-request-for-entitlement-values-with-leading-trailing-whitespace-cve-2024-1714/ - () https://www.sailpoint.com/security-advisories/sailpoint-identityiq-access-request-for-entitlement-values-with-leading-trailing-whitespace-cve-2024-1714/ -
Summary
  • (es) Existe un problema en todas las versiones compatibles de IdentityIQ Lifecycle Manager que puede surgir si un usuario autenticado solicita un derecho con un valor que contiene espacios en blanco al principio o al final en una solicitud de acceso.

06 Mar 2024, 17:15

Type Values Removed Values Added
CWE CWE-20
References
  • () https://www.sailpoint.com/security-advisories/sailpoint-identityiq-access-request-for-entitlement-values-with-leading-trailing-whitespace-cve-2024-1714/ -
Summary (en) Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. (en) An issue exists in all supported versions of IdentityIQ Lifecycle Manager that can result if an entitlement with a value containing leading or trailing whitespace is requested by an authenticated user in an access request.
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.1

21 Feb 2024, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-02-21 17:15

Updated : 2024-11-21 08:51


NVD link : CVE-2024-1714

Mitre link : CVE-2024-1714

CVE.ORG link : CVE-2024-1714


JSON object : View

Products Affected

No product.

CWE
CWE-20

Improper Input Validation