← Vulnerability feed

Vulnerability record · CVE-2022-46835 · published 31 January 2023

CVE-2022-46835: Sailpoint identityiq path traversal vulnerability

Sailpoint · Identityiq

IdentityIQ 8.3 and all 8.3 patch levels prior to 8.3p2, IdentityIQ 8.2 and all 8.2 patch levels prior to 8.2p5, IdentityIQ 8.1 and all 8.1 patch levels prior to 8.1p7, IdentityIQ 8.0 and all 8.0 patch levels prior to 8.0p6 allow access to arbitrary files in the application server filesystem due to a path traversal vulnerability in JavaServer Faces (JSF) 2.2.20 documented in CVE-2020-6950.

7.5 CVSS 3.1 High EPSS 0.94% · top 40.8% CWE-22 · Path traversal
7.5CVSS 3.1 base score
0.94%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

IdentityIQ 8.3 and all 8.3 patch levels prior to 8.3p2, IdentityIQ 8.2 and all 8.2 patch levels prior to 8.2p5, IdentityIQ 8.1 and all 8.1 patch levels prior to 8.1p7, IdentityIQ 8.0 and all 8.0 patch levels prior to 8.0p6 allow access to arbitrary files in the application server filesystem due to a path traversal vulnerability in JavaServer Faces (JSF) 2.2.20 documented in CVE-2020-6950.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-46835 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2026-12341Sailpoint identityiq improper authentication vulnerabilityThis vulnerability impacts all versions of IdentityIQ and allows an unauthenticated attacker unauthorized access to protected APIs and data due to im…EPSS 0.40%9.8CVE-2024-10905Sailpoint identityiq vulnerabilityIdentityIQ 8.4 and all 8.4 patch levels prior to 8.4p2, IdentityIQ 8.3 and all 8.3 patch levels prior to 8.3p5, IdentityIQ 8.2 and all 8.2 patch leve…EPSS 0.94%8.8CVE-2026-5712Sailpoint identityiq incorrect authorization vulnerabilityThis vulnerability impacts all versions of IdentityIQ and allows an authenticated identity that is the requestor or assignee of a work item to edit t…EPSS 0.29%8.8CVE-2024-2228Sailpoint identityiq improper privilege management vulnerabilityThis vulnerability allows an authenticated user to perform a Lifecycle Manager flow or other QuickLink for a target user outside of the defined Quick…EPSS 0.39%8.8CVE-2023-32217Sailpoint identityiq vulnerabilityIdentityIQ 8.3 and all 8.3 patch levels prior to 8.3p3, IdentityIQ 8.2 and all 8.2 patch levels prior to 8.2p6, IdentityIQ 8.1 and all 8.1 patch leve…EPSS 0.63%7.5CVE-2024-2227Sailpoint identityiq path traversal vulnerabilityThis vulnerability allows access to arbitrary files in the application server file system due to a path traversal vulnerability in JavaServer Faces (…EPSS 0.78%7.1CVE-2024-1714Sailpoint identityiq improper input validation vulnerabilityAn issue exists in all supported versions of IdentityIQ Lifecycle Manager that can result if an entitlement with a value containing leading or traili…EPSS 0.34%6.5CVE-2022-45435Sailpoint identityiq incorrect authorization vulnerabilityIdentityIQ 8.3 and all 8.3 patch levels prior to 8.3p2, IdentityIQ 8.2 and all 8.2 patch levels prior to 8.2p5, IdentityIQ 8.1 and all 8.1 patch leve…EPSS 0.39%

Source: NIST National Vulnerability Database (record CVE-2022-46835), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.