CVE-2024-10905SailPoint IdentityIQ directory traversal, CVSS 10.0
What broke
SailPoint IdentityIQ served protected static content through a directory-traversal / access-control gap. CVSS 10.0. Disclosed December 2024. SailPoint shipped e-fixes for 8.2p8, 8.3p5, and 8.4p2.
Why it matters
IGA is where joiner-mover-leaver actually happens. A CVSS 10 on IdentityIQ is not a web-app finding. It is a path to every entitlement model, every SOD rule, and often the service accounts IIQ uses to write to AD. We keep it in this catalog because 2025-2026 assessments still find unpatched 8.2/8.3.
What to do
- Apply the e-fix for your train. Confirm with SailPoint's advisory, not with "we are on 8.4."
- Take IdentityIQ off the internet. Put it behind SSO and an admin jump path.
- Review the 2025-2026 follow-ons: CVE-2025-10280 (XSS) and CVE-2026-5712 (role-editing authz).
After you patch
A governance platform holds connector credentials into most of your estate and can grant access by design, which makes it a high-value target rather than a reporting tool.
- Rotate every connector credential, since these are typically privileged service accounts in the systems being governed.
- Review entitlement changes, role assignments, and approvals recorded during the exposure window, and re-verify any that lack a matching request.
- Revoke sessions and API tokens on the platform itself, and check for administrative accounts added during the window.
- Re-run certification on privileged entitlements rather than assuming the last campaign is still valid. See access certification and what is IGA.
Sources
- NVD: CVE-2024-10905
- SailPoint e-fix advisories for IdentityIQ 8.2/8.3/8.4
Related identity CVEs
Related on Start with Identity
- CVESailPoint Identity Security Cloud access-control flaw
Identity Security Cloud (ISC) failed an access-control check. One of three 2024 ISC CVEs (3317/3318/3319) that still shape how we talk about SaaS IGA risk in 20
- CVESailPoint ISC connector path traversal
Identity Security Cloud connector configuration allowed path traversal. The 2025-2026 research notes that SCIM itself was quiet; provisioning risk sat in IdP an
- CVESailPoint ISC RCE via transform templates
Identity Security Cloud transform templates could be turned into remote code execution. Same class as Conjur's Ruby template injection, on the SaaS IGA side.
- Comparisonsailpoint-vs-saviynt
SailPoint has the deepest connector coverage for legacy and mainframe estates. Saviynt is cloud-native with stronger out-of-the-box SaaS and cloud access govern
- Comparisonveza-vs-sailpoint
Veza and SailPoint both address identity governance, but they enter from different angles. SailPoint is the established enterprise IGA platform covering the ful
- VendorBravura Security
niche