CVE-2022-45435
Estado: ModificadaMedia (6.5)—
IdentityIQ 8.3 and all 8.3 patch levels prior to 8.3p2, IdentityIQ 8.2 and all 8.2 patch levels prior to 8.2p5, IdentityIQ 8.1 and all 8.1 patch levels prior to 8.1p7, IdentityIQ 8.0 and all 8.0 patch levels prior to 8.0p6, and all prior versions allow authenticated users assigned the Identity Administrator capability or any custom capability that contains the SetIdentityForwarding right to modify the work item forwarding configuration for identities other than the ones that should be allowed by Lifecycle Manager Quicklink Population configuration.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
- Puntuación base: 6.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.39%
- Percentil entre todas las CVEs puntuadas: 31
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-863
- CWE-863
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2022-45435",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2022-45435",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2025-03-27T18:28:31.181114Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "psirt@sailpoint.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 6.8,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "HIGH",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.2,
"exploitabilityScore": 1.6
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 6.5,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "NONE"
},
"impactScore": 3.6,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "psirt@sailpoint.com",
"affectedData": [
{
"vendor": "SailPoint",
"product": "IdentityIQ",
"versions": [
{
"status": "affected",
"version": "8.3",
"versionType": "custom",
"lessThanOrEqual": "8.3p1"
},
{
"status": "affected",
"version": "8.2",
"versionType": "custom",
"lessThanOrEqual": "8.2p4"
},
{
"status": "affected",
"version": "8.1",
"versionType": "custom",
"lessThanOrEqual": "8.1p6"
},
{
"status": "affected",
"version": "8.0",
"versionType": "custom",
"lessThanOrEqual": "8.0p5"
}
]
}
]
}
],
"published": "2023-01-31T15:15:08.837",
"references": [
{
"url": "https://www.sailpoint.com/security-advisories/sailpoint-identityiq-identity-forwarding-vulnerability-cve-2022-45435/",
"tags": [
"Vendor Advisory"
],
"source": "psirt@sailpoint.com"
},
{
"url": "https://www.sailpoint.com/security-advisories/sailpoint-identityiq-identity-forwarding-vulnerability-cve-2022-45435/",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "psirt@sailpoint.com",
"description": [
{
"lang": "en",
"value": "CWE-863"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-863"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "IdentityIQ 8.3 and all 8.3 patch levels prior to 8.3p2, IdentityIQ 8.2 and all 8.2 patch levels prior to 8.2p5, IdentityIQ 8.1 and all 8.1 patch levels prior to 8.1p7, IdentityIQ 8.0 and all 8.0 patch levels prior to 8.0p6, and all prior versions allow authenticated users assigned the Identity Administrator capability or any custom capability that contains the SetIdentityForwarding right to modify the work item forwarding configuration for identities other than the ones that should be allowed by Lifecycle Manager Quicklink Population configuration."
},
{
"lang": "es",
"value": "IdentityIQ 8.3 y todos los niveles de parche 8.3 anteriores a 8.3p2, IdentityIQ 8.2 y todos los niveles de parche 8.2 anteriores a 8.2p5, IdentityIQ 8.1 y todos los niveles de parche 8.1 anteriores a 8.1p7, IdentityIQ 8.0 y todos los niveles de parche 8.0 anteriores a 8.0p6, y todos Las versiones anteriores permiten a los usuarios autenticados a los que se les ha asignado la capacidad de Administrador de identidades o cualquier capacidad personalizada que contenga el derecho SetIdentityForwarding modificar la configuración de reenvío de elementos de trabajo para identidades distintas a las que deberían permitirse mediante la configuración de Población de enlaces rápidos de Lifecycle Manager."
}
],
"lastModified": "2026-06-17T05:10:08.447",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:sailpoint:identityiq:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E3470BC7-4C59-4887-85FA-62E4CFCE31D4",
"versionEndExcluding": "8.0"
},
{
"criteria": "cpe:2.3:a:sailpoint:identityiq:8.0:-:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "331C62A4-620B-483A-87A6-9AA51679AF92"
},
{
"criteria": "cpe:2.3:a:sailpoint:identityiq:8.0:patch1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C84FC633-5B3C-4A40-A588-EF3AF509BBE9"
},
{
"criteria": "cpe:2.3:a:sailpoint:identityiq:8.0:patch2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6080940F-819D-468F-90B7-D1E135020777"
},
{
"criteria": "cpe:2.3:a:sailpoint:identityiq:8.0:patch3:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E018B45E-96CF-45C2-B405-3AFCC683BF9C"
},
{
"criteria": "cpe:2.3:a:sailpoint:identityiq:8.0:patch4:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CE18C753-3EE9-49C4-A99F-4429E0B20A1A"
},
{
"criteria": "cpe:2.3:a:sailpoint:identityiq:8.0:patch5:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F5641886-0FBB-472D-950A-70F94FB99087"
},
{
"criteria": "cpe:2.3:a:sailpoint:identityiq:8.1:-:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "00C8E5FB-5B6D-4C1B-AEFE-C884B28392D8"
},
{
"criteria": "cpe:2.3:a:sailpoint:identityiq:8.1:patch1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "216615A8-0E21-4597-871C-AC121BF0E150"
},
{
"criteria": "cpe:2.3:a:sailpoint:identityiq:8.1:patch2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "35ECC22F-B2A2-4750-B995-2944F12C1BFF"
},
{
"criteria": "cpe:2.3:a:sailpoint:identityiq:8.1:patch3:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9ECEF57B-DA34-402A-86F0-713A3683A172"
},
{
"criteria": "cpe:2.3:a:sailpoint:identityiq:8.1:patch4:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1815D4C7-50FC-45DA-8130-E9258CAFBD09"
},
{
"criteria": "cpe:2.3:a:sailpoint:identityiq:8.1:patch5:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F784765E-8B3C-4F96-B57A-E6E7AECE628C"
},
{
"criteria": "cpe:2.3:a:sailpoint:identityiq:8.1:patch6:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A7B4F481-4E74-4B56-9851-E1A665F5783D"
},
{
"criteria": "cpe:2.3:a:sailpoint:identityiq:8.2:-:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "224129BF-667F-4F6A-8E9A-15390F6FA3D5"
},
{
"criteria": "cpe:2.3:a:sailpoint:identityiq:8.2:patch1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2A8C2668-C1F1-4A67-A2B3-99B5746C6A52"
},
{
"criteria": "cpe:2.3:a:sailpoint:identityiq:8.2:patch2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A9D91EB5-EC8E-4200-9245-13E37312343D"
},
{
"criteria": "cpe:2.3:a:sailpoint:identityiq:8.2:patch4:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "63352C53-ADD8-49CD-B9E6-648183BDED68"
},
{
"criteria": "cpe:2.3:a:sailpoint:identityiq:8.3:-:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1173CC53-CBE5-450C-96BF-8583D1B3D185"
},
{
"criteria": "cpe:2.3:a:sailpoint:identityiq:8.3:patch1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2C0F5E55-5D33-425F-9DA7-49FE66CD84C4"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "psirt@sailpoint.com"
}