IdentityIQ JavaServer Faces File Path Traversal Vulnerability
Published Mar 22, 2024
10.0
CRITICALCVSS 3.1
EPSS 0.78%
Description
This vulnerability allows access to arbitrary files in the application server file system due to a path traversal vulnerability in JavaServer Faces (JSF) 2.2.20 documented in CVE-2020-6950. The remediation for this vulnerability contained in this security fix provides additional changes to the remediation announced in May 2021 tracked by ETN IIQSAW-3585 and January 2024 tracked by IIQFW-336. This vulnerability in IdentityIQ is assigned CVE-2024-2227.
Affected products
-
- Version 8.1StatusaffectedConstraints<8.1p7
- Version 8.2StatusaffectedConstraints<8.2p7
- Version 8.3StatusaffectedConstraints<8.3p4
- Version 8.4StatusaffectedConstraints<8.4p1
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| SailPoint | IdentityIQ | n/a |
|
- < 8.1
- 8.1
- 8.1
- 8.1
- 8.1
- 8.1
- 8.1
- 8.2
- 8.2
- 8.2
- 8.2
- 8.2
- 8.3
- 8.3
- 8.3
- 8.4
-
- Version 8.1StatusaffectedConstraints<8.1p7
- Version 8.2StatusaffectedConstraints<8.2p7
- Version 8.3StatusaffectedConstraints<8.3p4
- Version 8.4StatusaffectedConstraints<8.4p1
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Sailpoint | Identityiq | n/a |
|
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-27183 Advisory
- https://www.sailpoint.com/security-advisories/ Vendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-27183 | Advisory | |
| https://www.sailpoint.com/security-advisories/ | Vendor Advisory |
Change history (0)
No recorded changes yet.