← Vulnerability feed

Vulnerability record · CVE-2023-32217 · published 5 June 2023

CVE-2023-32217: Sailpoint identityiq vulnerability

Sailpoint · Identityiq

IdentityIQ 8.3 and all 8.3 patch levels prior to 8.3p3, IdentityIQ 8.2 and all 8.2 patch levels prior to 8.2p6, IdentityIQ 8.1 and all 8.1 patch levels prior to 8.1p7, IdentityIQ 8.0 and all 8.0 patch levels prior to 8.0p6 allow an authenticated user to invoke a Java constructor with no arguments or a Java constructor with a single Map argument in any Java class available in the IdentityIQ application classpath.

8.8 CVSS 3.1 High EPSS 0.63% · top 52.0% CWE-470 · CWE-470
8.8CVSS 3.1 base score
0.63%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

IdentityIQ 8.3 and all 8.3 patch levels prior to 8.3p3, IdentityIQ 8.2 and all 8.2 patch levels prior to 8.2p6, IdentityIQ 8.1 and all 8.1 patch levels prior to 8.1p7, IdentityIQ 8.0 and all 8.0 patch levels prior to 8.0p6 allow an authenticated user to invoke a Java constructor with no arguments or a Java constructor with a single Map argument in any Java class available in the IdentityIQ application classpath.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-32217 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2026-12341Sailpoint identityiq improper authentication vulnerabilityThis vulnerability impacts all versions of IdentityIQ and allows an unauthenticated attacker unauthorized access to protected APIs and data due to im…EPSS 0.40%9.8CVE-2024-10905Sailpoint identityiq vulnerabilityIdentityIQ 8.4 and all 8.4 patch levels prior to 8.4p2, IdentityIQ 8.3 and all 8.3 patch levels prior to 8.3p5, IdentityIQ 8.2 and all 8.2 patch leve…EPSS 0.94%8.8CVE-2026-5712Sailpoint identityiq incorrect authorization vulnerabilityThis vulnerability impacts all versions of IdentityIQ and allows an authenticated identity that is the requestor or assignee of a work item to edit t…EPSS 0.29%8.8CVE-2024-2228Sailpoint identityiq improper privilege management vulnerabilityThis vulnerability allows an authenticated user to perform a Lifecycle Manager flow or other QuickLink for a target user outside of the defined Quick…EPSS 0.39%7.5CVE-2024-2227Sailpoint identityiq path traversal vulnerabilityThis vulnerability allows access to arbitrary files in the application server file system due to a path traversal vulnerability in JavaServer Faces (…EPSS 0.78%7.5CVE-2022-46835Sailpoint identityiq path traversal vulnerabilityIdentityIQ 8.3 and all 8.3 patch levels prior to 8.3p2, IdentityIQ 8.2 and all 8.2 patch levels prior to 8.2p5, IdentityIQ 8.1 and all 8.1 patch leve…EPSS 0.94%7.1CVE-2024-1714Sailpoint identityiq improper input validation vulnerabilityAn issue exists in all supported versions of IdentityIQ Lifecycle Manager that can result if an entitlement with a value containing leading or traili…EPSS 0.34%6.5CVE-2022-45435Sailpoint identityiq incorrect authorization vulnerabilityIdentityIQ 8.3 and all 8.3 patch levels prior to 8.3p2, IdentityIQ 8.2 and all 8.2 patch levels prior to 8.2p5, IdentityIQ 8.1 and all 8.1 patch leve…EPSS 0.39%

Source: NIST National Vulnerability Database (record CVE-2023-32217), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.