logo

Perfect 10 directory traversal vuln hits SailPoint's IAM solution

ID: 721e2428-055d-5363-9aff-a578170d5de7

STIX ID: report--721e2428-055d-5363-9aff-a578170d5de7

Feed Name: The Register (Security)

Threat Score
75/100

Date Published: 2024-12-03

Date Updated: 2026-04-26

Author: Connor Jones

...
...

SailPoint IdentityIQ contains a critical directory traversal vulnerability tracked as CVE-2024-10905 (CWE-66) and rated 10/10 by the NVD; SailPoint published patched versions (8.4p2, 8.3p5, 8.2p8) for mitigation but no formal advisory or public evidence of exploitation has been reported, despite the product's use by major enterprises.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.