Security Advisory

CVE-2022-46835

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2023-01-31 00:00:00
Last updated 2025-03-27 18:26:57
Assigner SailPoint
State PUBLISHED

Description

IdentityIQ 8.3 and all 8.3 patch levels prior to 8.3p2, IdentityIQ 8.2 and all 8.2 patch levels prior to 8.2p5, IdentityIQ 8.1 and all 8.1 patch levels prior to 8.1p7, IdentityIQ 8.0 and all 8.0 patch levels prior to 8.0p6 allow access to arbitrary files in the application server filesystem due to a path traversal vulnerability in JavaServer Faces (JSF) 2.2.20 documented in CVE-2020-6950.