Vulnerability Description
An issue exists in all supported versions of IdentityIQ Lifecycle Manager that can result if an entitlement with a value containing leading or trailing whitespace is requested by an authenticated user in an access request.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sailpoint | Identityiq | 8.1 |
Related Weaknesses (CWE)
References
- https://www.sailpoint.com/security-advisories/sailpoint-identityiq-access-requesThird Party Advisory
- https://www.sailpoint.com/security-advisories/sailpoint-identityiq-access-requesThird Party Advisory
FAQ
What is CVE-2024-1714?
CVE-2024-1714 is a vulnerability with a CVSS score of 7.1 (HIGH). An issue exists in all supported versions of IdentityIQ Lifecycle Manager that can result if an entitlement with a value containing leading or trailing whitespace is requested by an authenticated user...
How severe is CVE-2024-1714?
CVE-2024-1714 has been rated HIGH with a CVSS base score of 7.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-1714?
Check the references section above for vendor advisories and patch information. Affected products include: Sailpoint Identityiq.