Vulnerability Description
IdentityIQ 8.3 and all 8.3 patch levels prior to 8.3p3, IdentityIQ 8.2 and all 8.2 patch levels prior to 8.2p6, IdentityIQ 8.1 and all 8.1 patch levels prior to 8.1p7, IdentityIQ 8.0 and all 8.0 patch levels prior to 8.0p6 allow an authenticated user to invoke a Java constructor with no arguments or a Java constructor with a single Map argument in any Java class available in the IdentityIQ application classpath.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sailpoint | Identityiq | 8.0 |
Related Weaknesses (CWE)
References
- https://www.sailpoint.com/security-advisories/sailpoint-identityiq-unsafe-use-ofVendor Advisory
- https://www.sailpoint.com/security-advisories/sailpoint-identityiq-unsafe-use-ofVendor Advisory
FAQ
What is CVE-2023-32217?
CVE-2023-32217 is a vulnerability with a CVSS score of 9.0 (CRITICAL). IdentityIQ 8.3 and all 8.3 patch levels prior to 8.3p3, IdentityIQ 8.2 and all 8.2 patch levels prior to 8.2p6, IdentityIQ 8.1 and all 8.1 patch levels prior to 8.1p7, IdentityIQ 8.0 and all 8.0 patch...
How severe is CVE-2023-32217?
CVE-2023-32217 has been rated CRITICAL with a CVSS base score of 9.0/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2023-32217?
Check the references section above for vendor advisories and patch information. Affected products include: Sailpoint Identityiq.