CVE Vulnerabilities

CVE-2024-2228

Improper Privilege Management

Published: Mar 22, 2024 | Modified: Nov 12, 2025
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

This vulnerability allows an authenticated user to perform a Lifecycle Manager flow or other QuickLink for a target user outside of the defined QuickLink Population.

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

NameVendorStart VersionEnd Version
IdentityiqSailpoint*8.1 (excluding)
IdentityiqSailpoint8.1-patch1 (including)8.1-patch1 (including)
IdentityiqSailpoint8.1-patch2 (including)8.1-patch2 (including)
IdentityiqSailpoint8.1-patch3 (including)8.1-patch3 (including)
IdentityiqSailpoint8.1-patch4 (including)8.1-patch4 (including)
IdentityiqSailpoint8.1-patch5 (including)8.1-patch5 (including)
IdentityiqSailpoint8.1-patch6 (including)8.1-patch6 (including)
IdentityiqSailpoint8.2 (including)8.2 (including)
IdentityiqSailpoint8.2-patch1 (including)8.2-patch1 (including)
IdentityiqSailpoint8.2-patch2 (including)8.2-patch2 (including)
IdentityiqSailpoint8.2-patch4 (including)8.2-patch4 (including)
IdentityiqSailpoint8.2-patch5 (including)8.2-patch5 (including)
IdentityiqSailpoint8.3 (including)8.3 (including)
IdentityiqSailpoint8.3-patch1 (including)8.3-patch1 (including)
IdentityiqSailpoint8.3-patch2 (including)8.3-patch2 (including)
IdentityiqSailpoint8.4 (including)8.4 (including)

Potential Mitigations

References