CVE-2023-32217: SailPoint IdentityIQ Unsafe use of Reflection Vulnerability
IdentityIQ 8.3 and all 8.3 patch levels prior to 8.3p3, IdentityIQ 8.2 and all 8.2 patch levels prior to 8.2p6, IdentityIQ 8.1 and all 8.1 patch levels prior to 8.1p7, IdentityIQ 8.0 and all 8.0 patch levels prior to 8.0p6 allow an authenticated user to invoke a Java constructor with no arguments or a Java constructor with a single Map argument in any Java class available in the IdentityIQ application classpath.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-32217?
CVE-2023-32217 is classified as a critical vulnerability affecting certain versions of SailPoint IdentityIQ.
How do I fix CVE-2023-32217?
To remediate CVE-2023-32217, upgrade to SailPoint IdentityIQ version 8.3p3 or higher, 8.2p6 or higher, 8.1p7 or higher, or 8.0p6 or higher.
What versions are affected by CVE-2023-32217?
CVE-2023-32217 affects SailPoint IdentityIQ versions 8.0 to 8.3, prior to specified patch levels.
Can CVE-2023-32217 be exploited without authentication?
No, CVE-2023-32217 requires an authenticated user to exploit the vulnerability.
What type of vulnerability is CVE-2023-32217?
CVE-2023-32217 is an insecure use of reflection vulnerability in SailPoint IdentityIQ.