VYPR

Identity Security Cloud

by Sailpoint

CVEs (2)

  • CVE-2024-3319CriMay 15, 2024
    risk 0.59cvss 9.1epss 0.04

    An issue was identified in the Identity Security Cloud (ISC) Transform preview and IdentityProfile preview API endpoints that allowed an authenticated administrator to execute user-defined templates as part of attribute transforms which could allow remote code execution on the…

  • CVE-2024-3317MedMay 15, 2024
    risk 0.42cvss 6.5epss 0.00

    An improper access control was identified in the Identity Security Cloud (ISC) message server API that allowed an authenticated user to exfiltrate job processing metadata (opaque messageIDs, work queue depth and counts) for other tenants.