CVE-2025-10280
Estado: AnalizadaMedia (6.1)—
IdentityIQ 8.5, IdentityIQ 8.4 and all 8.4 patch levels prior to 8.4p4, IdentityIQ 8.3 and all 8.3 patch levels including 8.3p5, and all prior versions allows some IdentityIQ web services that provide non-HTML content to be accessed via a URL path that will set the Content-Type to HTML allowing a requesting browser to interpret content not properly escaped to prevent Cross-Site Scripting (XSS).
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- Puntuación base: 6.1
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.22%
- Percentil entre todas las CVEs puntuadas: 11
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-79
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2025-10280",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-10280",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2025-11-04T04:55:16.675765Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "psirt@sailpoint.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.1,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "REQUIRED",
"attackComplexity": "HIGH",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 1.2
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 6.1,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
"integrityImpact": "LOW",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "LOW"
},
"impactScore": 2.7,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "psirt@sailpoint.com",
"affectedData": [
{
"vendor": "SailPoint Technologies",
"product": "IdentityIQ",
"versions": [
{
"status": "affected",
"version": "8.5",
"versionType": "semver"
},
{
"status": "affected",
"version": "8.4",
"lessThan": "8.4p4",
"versionType": "semver"
},
{
"status": "affected",
"version": "8.3",
"versionType": "semver",
"lessThanOrEqual": "8.3p5"
}
],
"defaultStatus": "affected"
}
]
}
],
"published": "2025-11-03T17:15:32.527",
"references": [
{
"url": "https://www.sailpoint.com/security-advisories/sailpoint-identityiq-incorrect-content-type-cross-site-scripting-vulnerability-cve-2025-10280",
"tags": [
"Vendor Advisory"
],
"source": "psirt@sailpoint.com"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "psirt@sailpoint.com",
"description": [
{
"lang": "en",
"value": "CWE-79"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "IdentityIQ\n8.5, IdentityIQ 8.4 and all 8.4 patch levels prior to 8.4p4, IdentityIQ 8.3 and\nall 8.3 patch levels including 8.3p5, and all prior versions allows some\nIdentityIQ web services that provide non-HTML content to be accessed via a URL\npath that will set the Content-Type to HTML allowing a requesting browser to\ninterpret content not properly escaped to prevent Cross-Site Scripting (XSS)."
}
],
"lastModified": "2026-06-17T08:28:03.070",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:sailpoint:identityiq:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B7992F80-093D-4277-9AA8-5438ABFBF83B",
"versionEndExcluding": "8.3"
},
{
"criteria": "cpe:2.3:a:sailpoint:identityiq:8.3:-:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1173CC53-CBE5-450C-96BF-8583D1B3D185"
},
{
"criteria": "cpe:2.3:a:sailpoint:identityiq:8.3:patch1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2C0F5E55-5D33-425F-9DA7-49FE66CD84C4"
},
{
"criteria": "cpe:2.3:a:sailpoint:identityiq:8.3:patch2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1A2FD228-E6DB-49E3-BE3E-1BF9B0434FC0"
},
{
"criteria": "cpe:2.3:a:sailpoint:identityiq:8.3:patch4:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0652D99D-DC1E-4E22-8E7D-AE080494C50B"
},
{
"criteria": "cpe:2.3:a:sailpoint:identityiq:8.3:patch5:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D7964011-B0F1-4F07-8C14-6EEA0B421F80"
},
{
"criteria": "cpe:2.3:a:sailpoint:identityiq:8.4:-:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4BC4F08D-A3FB-41F6-8EFD-6F34FBC0F75F"
},
{
"criteria": "cpe:2.3:a:sailpoint:identityiq:8.4:patch1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4ECFADA6-BB7B-4228-9434-B92B2FF21481"
},
{
"criteria": "cpe:2.3:a:sailpoint:identityiq:8.4:patch2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A39B1317-37C0-49DA-9207-7B7CBE6EC190"
},
{
"criteria": "cpe:2.3:a:sailpoint:identityiq:8.5:-:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "01FF7480-9CBA-4283-994C-B2586C2F5F54"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "psirt@sailpoint.com"
}