CVE-2024-10905CWE-66

IdentityIQ Improper Access Control VulnerabilityIdentityIQ Improper Access Control Vulnerability

Critical · published December 2, 2024

CVSS v3.1
10.0
EPSS
1%
Percentile
58.9
In the wild
Unconfirmed
What it is

🔥 A critical oversight allows HTTP/HTTPS access to sensitive static content in IdentityIQ versions before 8.4p2! What could go wrong? Just about everything! ⚡ Think of it like a restaurant that accidentally leaves the kitchen door wide open. Anyone can stroll in and see the recipe book or even tamper with the ingredients — it's a recipe for disaster! An attacker could exploit this vulnerability to access confidential application data or static paths, potentially leading to unauthorized access to sensitive information. Imagine a malicious actor walking right into your server's kitchen and grabbing anything they want – absolutely devastating!

Put simply

Think of it like a restaurant that accidentally leaves the kitchen door wide open. Anyone can stroll in and see the recipe book or even tamper with the ingredients — it's a recipe for disaster! This vulnerability stems from improper access controls in IdentityIQ, allowing attackers to reach static content in the application directory that should be protected. Versions affected include IdentityIQ 8.4 and earlier, with specific patch levels that need updating.

What to do

An attacker could exploit this vulnerability to access confidential application data or static paths, potentially leading to unauthorized access to sensitive information. Imagine a malicious actor walking right into your server's kitchen and grabbing anything they want – absolutely devastating! To safeguard your environment, update to IdentityIQ version 8.4p2, 8.3p5, or 8.2p8 at a minimum. Additionally, tighten your access controls to ensure only authorized users can access sensitive directories. Don't wait—act swiftly! This is fixable! Patch your systems and you'll be well on your way to securing your application! 🛡️

The record
Technical detail
CVSS v3.1
10.0 · CRITICAL
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CVSS v4.0
Not supplied
EPSS
0.00946 · 58.9th percentile
Weakness
CWE-66 · Improper Handling of File Names that Identify Virtual Resources
Published
2024-12-02T14:49Z
EPSS history
Timeline
  • 02 DEC 14:49Z
    IdentityIQ Improper Access Control VulnerabilityIdentityIQ Improper Access Control Vulnerability
    cvelistv5