CVE-2023-32217 is a critical vulnerability affecting SailPoint IdentityIQ versions 8.3 (prior to 8.3p3), 8.2 (prior to 8.2p6), 8.1 (prior to 8.1p7), and 8.0 (prior to 8.0p6). This flaw allows an authenticated user to invoke Java constructors with specific argument types in any class within the application's classpath, categorized as a CWE-470 (Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')). With a CVSS score of 8.8 (HIGH), the vulnerability presents a significant risk due to its low attack complexity (AC:L) and the potential for complete compromise of confidentiality, integrity, and availability (C:H/I:H/A:H) once an attacker gains authenticated access (PR:L). The attack vector is over the network (AV:N), meaning it can be exploited remotely. Currently, there is no evidence of active exploitation, and no public exploit code is available on platforms like Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage are minimal, suggesting a low level of public awareness despite its high severity.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
8.0CPE matchmatch criteria | cpe:2.3:a:sailpoint:identityiq:8.0:-:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:a:sailpoint:identityiq:8.0:patch1:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:a:sailpoint:identityiq:8.0:patch2:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:a:sailpoint:identityiq:8.0:patch3:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:a:sailpoint:identityiq:8.0:patch4:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
SailPoint IdentityIQ Unsafe use of Reflection Vulnerability- CVE-2023-32217
SailPoint IdentityIQ Unsafe use of Reflection Vulnerability- CVE-2023-32217
SailPoint IdentityIQ Unsafe use of Reflection Vulnerability- CVE-2023-32217