CVE-2022-46835: SailPoint IdentityIQ JavaServer File Path Traversal Vulnerability
IdentityIQ 8.3 and all 8.3 patch levels prior to 8.3p2, IdentityIQ 8.2 and all 8.2 patch levels prior to 8.2p5, IdentityIQ 8.1 and all 8.1 patch levels prior to 8.1p7, IdentityIQ 8.0 and all 8.0 patch levels prior to 8.0p6 allow access to arbitrary files in the application server filesystem due to a path traversal vulnerability in JavaServer Faces (JSF) 2.2.20 documented in CVE-2020-6950.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-46835?
CVE-2022-46835 has a high severity due to its risk of arbitrary file access.
How do I fix CVE-2022-46835?
To fix CVE-2022-46835, update to IdentityIQ version 8.3p2 or later, 8.2p5 or later, 8.1p7 or later, or 8.0p6 or later.
What versions are affected by CVE-2022-46835?
CVE-2022-46835 affects IdentityIQ versions 8.0, 8.1, 8.2, and 8.3 prior to their respective patch levels.
What kind of vulnerability is CVE-2022-46835?
CVE-2022-46835 is a file traversal vulnerability that allows unauthorized access to arbitrary files.
Is CVE-2022-46835 exploitable remotely?
Yes, CVE-2022-46835 is exploitable remotely, allowing attackers to access sensitive files on the server.