Start with Identity
Identity CVE · IGA

CVE-2024-3317SailPoint Identity Security Cloud access-control flaw

high
Product: SailPoint Identity Security CloudVendor: SailPointDisclosed: 2024-04-10Status: PatchedNVD ↗

What broke

SailPoint Identity Security Cloud did not enforce an access-control check. CVE-2024-3317 is the access-control ID in a three-bug set with connector path traversal and RCE via transform templates. SailPoint patched the SaaS side.

Why it matters

SaaS IGA feels like "SailPoint will patch it." The customer still has to rotate connectors, review who can edit transforms, and treat ISC like the privileged system it is. We keep the 2024 ISC set in this catalog because the 2025-2026 IdentityIQ bugs are the same story on-prem.

What to do

  • Confirm SailPoint applied the ISC fix in your tenant. SaaS patches are not always simultaneous.
  • Review API tokens and admin roles in ISC the way you would after an IdP incident.

Sources

Know a primary source we should add, or a patch status that has changed? Email [email protected]. See all briefs in the identity CVE catalog, or volunteer as a CVE Analyst.
Compiled from vendor advisories, NVD, CISA KEV, and public research. CVSS figures can disagree across NVD and the CNA. Confirm affected versions against the vendor advisory before you patch. Independent, community-driven analysis. See the disclaimer.