CVE-2024-1714

An issue exists in all supported versions of IdentityIQ Lifecycle Manager that can result if an entitlement with a value containing leading or trailing whitespace is requested by an authenticated user in an access request.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:sailpoint:identityiq:8.1:-:*:*:*:*:*:*
cpe:2.3:a:sailpoint:identityiq:8.1:patch1:*:*:*:*:*:*
cpe:2.3:a:sailpoint:identityiq:8.1:patch2:*:*:*:*:*:*
cpe:2.3:a:sailpoint:identityiq:8.1:patch3:*:*:*:*:*:*
cpe:2.3:a:sailpoint:identityiq:8.1:patch4:*:*:*:*:*:*
cpe:2.3:a:sailpoint:identityiq:8.1:patch5:*:*:*:*:*:*
cpe:2.3:a:sailpoint:identityiq:8.1:patch6:*:*:*:*:*:*
cpe:2.3:a:sailpoint:identityiq:8.2:-:*:*:*:*:*:*
cpe:2.3:a:sailpoint:identityiq:8.2:patch1:*:*:*:*:*:*
cpe:2.3:a:sailpoint:identityiq:8.2:patch2:*:*:*:*:*:*
cpe:2.3:a:sailpoint:identityiq:8.2:patch4:*:*:*:*:*:*
cpe:2.3:a:sailpoint:identityiq:8.3:-:*:*:*:*:*:*
cpe:2.3:a:sailpoint:identityiq:8.3:patch1:*:*:*:*:*:*
cpe:2.3:a:sailpoint:identityiq:8.4:-:*:*:*:*:*:*

History

06 May 2025, 17:45

Type Values Removed Values Added
CPE cpe:2.3:a:sailpoint:identityiq:8.1:patch2:*:*:*:*:*:*
cpe:2.3:a:sailpoint:identityiq:8.1:patch4:*:*:*:*:*:*
cpe:2.3:a:sailpoint:identityiq:8.3:-:*:*:*:*:*:*
cpe:2.3:a:sailpoint:identityiq:8.2:patch4:*:*:*:*:*:*
cpe:2.3:a:sailpoint:identityiq:8.1:patch3:*:*:*:*:*:*
cpe:2.3:a:sailpoint:identityiq:8.1:patch1:*:*:*:*:*:*
cpe:2.3:a:sailpoint:identityiq:8.1:-:*:*:*:*:*:*
cpe:2.3:a:sailpoint:identityiq:8.1:patch5:*:*:*:*:*:*
cpe:2.3:a:sailpoint:identityiq:8.4:-:*:*:*:*:*:*
cpe:2.3:a:sailpoint:identityiq:8.3:patch1:*:*:*:*:*:*
cpe:2.3:a:sailpoint:identityiq:8.1:patch6:*:*:*:*:*:*
cpe:2.3:a:sailpoint:identityiq:8.2:patch1:*:*:*:*:*:*
cpe:2.3:a:sailpoint:identityiq:8.2:-:*:*:*:*:*:*
cpe:2.3:a:sailpoint:identityiq:8.2:patch2:*:*:*:*:*:*
First Time Sailpoint identityiq
Sailpoint
References () https://www.sailpoint.com/security-advisories/sailpoint-identityiq-access-request-for-entitlement-values-with-leading-trailing-whitespace-cve-2024-1714/ - () https://www.sailpoint.com/security-advisories/sailpoint-identityiq-access-request-for-entitlement-values-with-leading-trailing-whitespace-cve-2024-1714/ - Third Party Advisory

18 Dec 2024, 18:15

Type Values Removed Values Added
CWE CWE-1284

21 Nov 2024, 08:51

Type Values Removed Values Added
Summary
  • (es) Existe un problema en todas las versiones compatibles de IdentityIQ Lifecycle Manager que puede surgir si un usuario autenticado solicita un derecho con un valor que contiene espacios en blanco al principio o al final en una solicitud de acceso.
References () https://www.sailpoint.com/security-advisories/sailpoint-identityiq-access-request-for-entitlement-values-with-leading-trailing-whitespace-cve-2024-1714/ - () https://www.sailpoint.com/security-advisories/sailpoint-identityiq-access-request-for-entitlement-values-with-leading-trailing-whitespace-cve-2024-1714/ -

06 Mar 2024, 17:15

Type Values Removed Values Added
CWE CWE-20
Summary (en) Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. (en) An issue exists in all supported versions of IdentityIQ Lifecycle Manager that can result if an entitlement with a value containing leading or trailing whitespace is requested by an authenticated user in an access request.
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.1
References
  • () https://www.sailpoint.com/security-advisories/sailpoint-identityiq-access-request-for-entitlement-values-with-leading-trailing-whitespace-cve-2024-1714/ -

21 Feb 2024, 18:15

Type Values Removed Values Added
Summary (en) An issue exists in all supported versions of IdentityIQ Lifecycle Manager that can result if an entitlement with a value containing leading or trailing whitespace is requested by an authenticated user in an access request. (en) Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CWE CWE-20
References
  • {'url': 'https://www.sailpoint.com/security-advisories/', 'source': 'psirt@sailpoint.com'}
CVSS v2 : unknown
v3 : 7.1
v2 : unknown
v3 : unknown

21 Feb 2024, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-02-21 17:15

Updated : 2025-05-06 17:45


NVD link : CVE-2024-1714

Mitre link : CVE-2024-1714

CVE.ORG link : CVE-2024-1714


JSON object : View

Products Affected

sailpoint

  • identityiq
CWE
CWE-20

Improper Input Validation

CWE-1284

Improper Validation of Specified Quantity in Input