cve/2024/CVE-2024-10905.md
2025-09-29 21:09:30 +02:00

20 lines
1014 B
Markdown
Raw Blame History

This file contains invisible Unicode characters

This file contains invisible Unicode characters that are indistinguishable to humans but may be processed differently by a computer. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

### [CVE-2024-10905](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-10905)
![](https://img.shields.io/static/v1?label=Product&message=IdentityIQ&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=8.2%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=8.3%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=8.4%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-66%3A%20Improper%20Handling%20of%20File%20Names%20that%20Identify%20Virtual%20Resources&color=brightgreen)
### Description
IdentityIQ 8.4 and all 8.4 patch levels prior to 8.4p2, IdentityIQ 8.3 and all 8.3 patch levels prior to 8.3p5, IdentityIQ 8.2 and all 8.2 patch levels prior to 8.2p8, and all prior versions allow HTTP/HTTPS access to static content in the IdentityIQ application directory that should be protected.
### POC
#### Reference
No PoCs from references.
#### Github
- https://github.com/Ostorlab/KEV