漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
IdentityIQ Role Editor Incorrect Authorization Vulnerability
Vulnerability Description
This vulnerability impacts all versions of IdentityIQ and allows an authenticated identity that is the requestor or assignee of a work item to edit the definition of a role without having an assigned capability that would allow role editing.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H
Vulnerability Type
授权机制不正确
Vulnerability Title
SailPoint IdentityIQ 安全漏洞
Vulnerability Description
SailPoint IdentityIQ是SailPoint公司的一款安全软件。提供信用监控、身份保险和防病毒。 SailPoint IdentityIQ存在安全漏洞,该漏洞源于允许作为工作项请求者或分配人的已认证身份编辑角色定义,而无需具备允许角色编辑的分配能力。
CVSS Information
N/A
Vulnerability Type
N/A