Vulnerability Database

318,389

Total vulnerabilities in the database

CVE-2022-46835

IdentityIQ 8.3 and all 8.3 patch levels prior to 8.3p2, IdentityIQ 8.2 and all 8.2 patch levels prior to 8.2p5, IdentityIQ 8.1 and all 8.1 patch levels prior to 8.1p7, IdentityIQ 8.0 and all 8.0 patch levels prior to 8.0p6 allow access to arbitrary files in the application server filesystem due to a path traversal vulnerability in JavaServer Faces (JSF) 2.2.20 documented in CVE-2020-6950.

  • Published: Jan 31, 2023
  • Updated: Nov 16, 2025
  • CVE: CVE-2022-46835
  • Severity: High
  • Exploit:

CVSS v3:

  • Severity: High
  • Score: 8.8
  • AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Software From Fixed in
sailpoint / identityiq 8.3 8.3.x
sailpoint / identityiq 8.3-patch1 8.3-patch1.x
sailpoint / identityiq 8.2-patch1 8.2-patch1.x
sailpoint / identityiq 8.2-patch2 8.2-patch2.x
sailpoint / identityiq 8.2-patch4 8.2-patch4.x
sailpoint / identityiq 8.2 8.2.x
sailpoint / identityiq 8.1-patch6 8.1-patch6.x
sailpoint / identityiq 8.1-patch1 8.1-patch1.x
sailpoint / identityiq 8.1-patch2 8.1-patch2.x
sailpoint / identityiq 8.1-patch3 8.1-patch3.x
sailpoint / identityiq 8.1-patch4 8.1-patch4.x
sailpoint / identityiq 8.1-patch5 8.1-patch5.x
sailpoint / identityiq 8.1 8.1.x
sailpoint / identityiq 8.0-patch1 8.0-patch1.x
sailpoint / identityiq 8.0-patch2 8.0-patch2.x
sailpoint / identityiq 8.0-patch3 8.0-patch3.x
sailpoint / identityiq 8.0-patch4 8.0-patch4.x
sailpoint / identityiq 8.0-patch5 8.0-patch5.x
sailpoint / identityiq 8.0 8.0.x