← Vulnerability feed

Vulnerability record · CVE-2024-2228 · published 22 March 2024

CVE-2024-2228: Sailpoint identityiq improper privilege management vulnerability

Sailpoint · Identityiq

This vulnerability allows an authenticated user to perform a Lifecycle Manager flow or other QuickLink for a target user outside of the defined QuickLink Population.

8.8 CVSS 3.1 High EPSS 0.39% · top 69.8% CWE-269 · Improper privilege management
8.8CVSS 3.1 base score
0.39%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

This vulnerability allows an authenticated user to perform a Lifecycle Manager flow or other QuickLink for a target user outside of the defined QuickLink Population.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-2228 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2026-12341Sailpoint identityiq improper authentication vulnerabilityThis vulnerability impacts all versions of IdentityIQ and allows an unauthenticated attacker unauthorized access to protected APIs and data due to im…EPSS 0.40%9.8CVE-2024-10905Sailpoint identityiq vulnerabilityIdentityIQ 8.4 and all 8.4 patch levels prior to 8.4p2, IdentityIQ 8.3 and all 8.3 patch levels prior to 8.3p5, IdentityIQ 8.2 and all 8.2 patch leve…EPSS 0.94%8.8CVE-2026-5712Sailpoint identityiq incorrect authorization vulnerabilityThis vulnerability impacts all versions of IdentityIQ and allows an authenticated identity that is the requestor or assignee of a work item to edit t…EPSS 0.29%8.8CVE-2023-32217Sailpoint identityiq vulnerabilityIdentityIQ 8.3 and all 8.3 patch levels prior to 8.3p3, IdentityIQ 8.2 and all 8.2 patch levels prior to 8.2p6, IdentityIQ 8.1 and all 8.1 patch leve…EPSS 0.63%7.5CVE-2024-2227Sailpoint identityiq path traversal vulnerabilityThis vulnerability allows access to arbitrary files in the application server file system due to a path traversal vulnerability in JavaServer Faces (…EPSS 0.78%7.5CVE-2022-46835Sailpoint identityiq path traversal vulnerabilityIdentityIQ 8.3 and all 8.3 patch levels prior to 8.3p2, IdentityIQ 8.2 and all 8.2 patch levels prior to 8.2p5, IdentityIQ 8.1 and all 8.1 patch leve…EPSS 0.94%7.1CVE-2024-1714Sailpoint identityiq improper input validation vulnerabilityAn issue exists in all supported versions of IdentityIQ Lifecycle Manager that can result if an entitlement with a value containing leading or traili…EPSS 0.34%6.5CVE-2022-45435Sailpoint identityiq incorrect authorization vulnerabilityIdentityIQ 8.3 and all 8.3 patch levels prior to 8.3p2, IdentityIQ 8.2 and all 8.2 patch levels prior to 8.2p5, IdentityIQ 8.1 and all 8.1 patch leve…EPSS 0.39%

Source: NIST National Vulnerability Database (record CVE-2024-2228), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.