Identityiq
Vendor:
First CVE: Jan 31, 2023 · Active for 3 years
9
Total CVEs
More Total CVEs than 88% of tracked products
2.3
Avg CVEs / Year
Higher CVE frequency than 76% of tracked products
7.9
Avg CVSS
Higher Avg CVSS than 70% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Identityiq over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jan 31, 2023
3 years ago
Most Recent CVE
Apr 29, 2026
90 days ago
CVE Severity & Scoring
Identityiq9 CVEs
22%
67%
11%
All CVEs353,173 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network9 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (88.9%)
High1 (11.1%)
Unknown0 (0.0%)
User Interaction
None7 (77.8%)
Unknown0 (0.0%)
Required2 (22.2%)
Privileges Required
Low5 (55.6%)
High0 (0.0%)
None4 (44.4%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-5712HIGH This vulnerability impacts all versions of IdentityIQ and allows an authenticated identity that is the requestor or assignee of a work item to edit the definition of a role without | Apr 29, 2026 | 8.8 | 32 | NO | NO |
CVE-2024-10905CRITICAL IdentityIQ 8.4 and all 8.4 patch levels prior to 8.4p2, IdentityIQ 8.3 and all 8.3 patch levels prior to 8.3p5, IdentityIQ 8.2 and all 8.2 patch levels prior to 8.2p8, and all prio | Dec 2, 2024 | 9.8 | 31 | NO | NO |
CVE-2023-32217HIGH IdentityIQ 8.3 and all 8.3 patch levels prior to 8.3p3, IdentityIQ 8.2 and all 8.2 patch levels prior to 8.2p6, IdentityIQ 8.1 and all 8.1 patch levels prior to 8.1p7, IdentityIQ 8 | Jun 5, 2023 | 8.8 | 25 | NO | NO |
CVE-2022-46835HIGH IdentityIQ 8.3 and all 8.3 patch levels prior to 8.3p2, IdentityIQ 8.2 and all 8.2 patch levels prior to 8.2p5, IdentityIQ 8.1 and all 8.1 patch levels prior to 8.1p7, IdentityIQ 8 | Jan 31, 2023 | 7.5 | 25 | NO | NO |
CVE-2024-2228HIGH This vulnerability allows an authenticated user to perform a Lifecycle Manager flow or other QuickLink for a target user outside of the defined QuickLink Population. | Mar 22, 2024 | 8.8 | 23 | NO | NO |
CVE-2022-45435MEDIUM IdentityIQ 8.3 and all 8.3 patch levels prior to 8.3p2, IdentityIQ 8.2 and all 8.2 patch levels prior to 8.2p5, IdentityIQ 8.1 and all 8.1 patch levels prior to 8.1p7, IdentityIQ 8 | Jan 31, 2023 | 6.5 | 23 | NO | NO |
CVE-2024-2227HIGH This vulnerability allows access to arbitrary files in the application server file system due to a path traversal vulnerability in JavaServer Faces (JSF) 2.2.20 documented in CVE-2 | Mar 22, 2024 | 7.5 | 22 | NO | NO |
CVE-2025-10280MEDIUM IdentityIQ
8.5, IdentityIQ 8.4 and all 8.4 patch levels prior to 8.4p4, IdentityIQ 8.3 and
all 8.3 patch levels including 8.3p5, and all prior versions allows some
IdentityIQ web s | Nov 3, 2025 | 6.1 | 21 | NO | NO |
CVE-2024-1714HIGH An issue exists in all supported versions of IdentityIQ Lifecycle Manager that can result if an entitlement with a value containing leading or trailing whitespace is requested by a | Feb 21, 2024 | 7.1 | 18 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (9 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (9 CVEs).
Media Mentions
Signals from CVEs in this product scope (9 CVEs).
Top CNAs Publishing CVEs For Identityiq
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 8.5 | 2 | 7.9 | 0.2% | 0 | 0 |
| 8.4 | 6 | 8.0 | 0.4% | 0 | 0 |
| 8.3 | 9 | 7.9 | 0.5% | 0 | 0 |
| 8.2 | 7 | 8.1 | 0.7% | 0 | 0 |
| 8.1 | 6 | 7.7 | 0.6% | 0 | 0 |
| 8.0 | 3 | 7.5 | 0.7% | 0 | 0 |