CVE-2025-10280
Unknown
Unknown - Not Provided
BaseFortify
Publication date: 2025-11-03
Last updated on: 2025-11-12
Assigner: SailPoint Technologies
Description
Description
IdentityIQ
8.5, IdentityIQ 8.4 and all 8.4 patch levels prior to 8.4p4, IdentityIQ 8.3 and
all 8.3 patch levels including 8.3p5, and all prior versions allows some
IdentityIQ web services that provide non-HTML content to be accessed via a URL
path that will set the Content-Type to HTML allowing a requesting browser to
interpret content not properly escaped to prevent Cross-Site Scripting (XSS).
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| sailpoint | identityiq | to 8.3 (exc) |
| sailpoint | identityiq | 8.3 |
| sailpoint | identityiq | 8.3 |
| sailpoint | identityiq | 8.3 |
| sailpoint | identityiq | 8.3 |
| sailpoint | identityiq | 8.3 |
| sailpoint | identityiq | 8.4 |
| sailpoint | identityiq | 8.4 |
| sailpoint | identityiq | 8.4 |
| sailpoint | identityiq | 8.5 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-79 | The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users. |