back to article Perfect 10 directory traversal vuln hits SailPoint's IAM solution

It's time to rev up those patch engines after SailPoint disclosed a perfect 10/10 severity vulnerability in its identity and access management (IAM) platform IdentityIQ. The bug is not attached to a security advisory at the time of writing, but the vulnerability was reported on Monday to the National Vulnerability Database ( …

  1. Anonymous Coward
    Anonymous Coward

    Perfect 10 directory vulnerability

    Damn.

    I thought it was going to be a vulnerability in the directory of Perfect 10 models.

    1. Tom Chiverton 1

      Re: Perfect 10 directory vulnerability

      The ones that wear a 12?

  2. wub

    Counting blessings.

    Well, at least none of SailPoint's clients are telecoms, right? Right???

  3. Tom Chiverton 1
    Joke

    CWE-66

    That's pronounced "sea wee sixty six" right?

    1. Brewster's Angle Grinder Silver badge

      Re: CWE-66

      No "Queexty". As in "queexty, fix the damn thing!"

  4. Oh Homer
    Headmaster

    Not excusing the vendor but...

    Shouldn't their corporate customers be using secure platforms locked down with Mandatory Access Controls, instead of just haplessly relying on application security?

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon

Other stories you might like