← Vulnerability feed

Vulnerability record · CVE-2024-2227 · published 22 March 2024

CVE-2024-2227: Sailpoint identityiq path traversal vulnerability

Sailpoint · Identityiq

This vulnerability allows access to arbitrary files in the application server file system due to a path traversal vulnerability in JavaServer Faces (JSF) 2.2.20 documented in CVE-2020-6950. The remediation for this vulnerability contained in this security fix provides additional changes to the remediation announced in May 2021 tracked by ETN IIQSAW-3585 and January 2024 tracked by IIQFW-336. This vulnerability in IdentityIQ is assigned CVE-2024-2227.

7.5 CVSS 3.1 High EPSS 0.78% · top 45.9% CWE-22 · Path traversal
7.5CVSS 3.1 base score
0.78%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

This vulnerability allows access to arbitrary files in the application server file system due to a path traversal vulnerability in JavaServer Faces (JSF) 2.2.20 documented in CVE-2020-6950. The remediation for this vulnerability contained in this security fix provides additional changes to the remediation announced in May 2021 tracked by ETN IIQSAW-3585 and January 2024 tracked by IIQFW-336. This vulnerability in IdentityIQ is assigned CVE-2024-2227.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-2227 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2026-12341Sailpoint identityiq improper authentication vulnerabilityThis vulnerability impacts all versions of IdentityIQ and allows an unauthenticated attacker unauthorized access to protected APIs and data due to im…EPSS 0.40%9.8CVE-2024-10905Sailpoint identityiq vulnerabilityIdentityIQ 8.4 and all 8.4 patch levels prior to 8.4p2, IdentityIQ 8.3 and all 8.3 patch levels prior to 8.3p5, IdentityIQ 8.2 and all 8.2 patch leve…EPSS 0.94%8.8CVE-2026-5712Sailpoint identityiq incorrect authorization vulnerabilityThis vulnerability impacts all versions of IdentityIQ and allows an authenticated identity that is the requestor or assignee of a work item to edit t…EPSS 0.29%8.8CVE-2024-2228Sailpoint identityiq improper privilege management vulnerabilityThis vulnerability allows an authenticated user to perform a Lifecycle Manager flow or other QuickLink for a target user outside of the defined Quick…EPSS 0.39%8.8CVE-2023-32217Sailpoint identityiq vulnerabilityIdentityIQ 8.3 and all 8.3 patch levels prior to 8.3p3, IdentityIQ 8.2 and all 8.2 patch levels prior to 8.2p6, IdentityIQ 8.1 and all 8.1 patch leve…EPSS 0.63%7.5CVE-2022-46835Sailpoint identityiq path traversal vulnerabilityIdentityIQ 8.3 and all 8.3 patch levels prior to 8.3p2, IdentityIQ 8.2 and all 8.2 patch levels prior to 8.2p5, IdentityIQ 8.1 and all 8.1 patch leve…EPSS 0.94%7.1CVE-2024-1714Sailpoint identityiq improper input validation vulnerabilityAn issue exists in all supported versions of IdentityIQ Lifecycle Manager that can result if an entitlement with a value containing leading or traili…EPSS 0.34%6.5CVE-2022-45435Sailpoint identityiq incorrect authorization vulnerabilityIdentityIQ 8.3 and all 8.3 patch levels prior to 8.3p2, IdentityIQ 8.2 and all 8.2 patch levels prior to 8.2p5, IdentityIQ 8.1 and all 8.1 patch leve…EPSS 0.39%

Source: NIST National Vulnerability Database (record CVE-2024-2227), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.