Start with Identity
Identity CVE · IGA

CVE-2024-10905SailPoint IdentityIQ directory traversal, CVSS 10.0

critical · CVSS 10.0
Product: SailPoint IdentityIQVendor: SailPointDisclosed: 2024-12-16Status: PatchedNVD ↗

What broke

SailPoint IdentityIQ served protected static content through a directory-traversal / access-control gap. CVSS 10.0. Disclosed December 2024. SailPoint shipped e-fixes for 8.2p8, 8.3p5, and 8.4p2.

Why it matters

IGA is where joiner-mover-leaver actually happens. A CVSS 10 on IdentityIQ is not a web-app finding. It is a path to every entitlement model, every SOD rule, and often the service accounts IIQ uses to write to AD. We keep it in this catalog because 2025-2026 assessments still find unpatched 8.2/8.3.

What to do

  • Apply the e-fix for your train. Confirm with SailPoint's advisory, not with "we are on 8.4."
  • Take IdentityIQ off the internet. Put it behind SSO and an admin jump path.
  • Review the 2025-2026 follow-ons: CVE-2025-10280 (XSS) and CVE-2026-5712 (role-editing authz).

Sources

Know a primary source we should add, or a patch status that has changed? Email [email protected]. See all briefs in the identity CVE catalog, or volunteer as a CVE Analyst.
Compiled from vendor advisories, NVD, CISA KEV, and public research. CVSS figures can disagree across NVD and the CNA. Confirm affected versions against the vendor advisory before you patch. Independent, community-driven analysis. See the disclaimer.