Vulnerabilities
Vulnerable Software
Sailpoint:  >> Identityiq  >> 8.5  Security Vulnerabilities
This vulnerability impacts all versions of IdentityIQ and allows an authenticated identity that is the requestor or assignee of a work item to edit the definition of a role without having an assigned capability that would allow role editing.
CVSS Score
8.0
EPSS Score
0.0
Published
2026-04-29
IdentityIQ 8.5, IdentityIQ 8.4 and all 8.4 patch levels prior to 8.4p4, IdentityIQ 8.3 and all 8.3 patch levels including 8.3p5, and all prior versions allows some IdentityIQ web services that provide non-HTML content to be accessed via a URL path that will set the Content-Type to HTML allowing a requesting browser to interpret content not properly escaped to prevent Cross-Site Scripting (XSS).
CVSS Score
7.1
EPSS Score
0.0
Published
2025-11-03


Contact Us

Shodan ® - All rights reserved