IdentityIQ
8.5, IdentityIQ 8.4 and all 8.4 patch levels prior to 8.4p4, IdentityIQ 8.3 and
all 8.3 patch levels including 8.3p5, and all prior versions allows some
IdentityIQ web services that provide non-HTML content to be accessed via a URL
path that will set the Content-Type to HTML allowing a requesting browser to
interpret content not properly escaped to prevent Cross-Site Scripting (XSS).
References
Configurations
Configuration 1 (hide)
|
History
12 Nov 2025, 14:49
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:sailpoint:identityiq:8.3:-:*:*:*:*:*:* cpe:2.3:a:sailpoint:identityiq:8.4:-:*:*:*:*:*:* cpe:2.3:a:sailpoint:identityiq:8.5:-:*:*:*:*:*:* cpe:2.3:a:sailpoint:identityiq:8.4:patch1:*:*:*:*:*:* cpe:2.3:a:sailpoint:identityiq:8.3:patch4:*:*:*:*:*:* cpe:2.3:a:sailpoint:identityiq:*:*:*:*:*:*:*:* cpe:2.3:a:sailpoint:identityiq:8.3:patch1:*:*:*:*:*:* cpe:2.3:a:sailpoint:identityiq:8.4:patch2:*:*:*:*:*:* cpe:2.3:a:sailpoint:identityiq:8.3:patch2:*:*:*:*:*:* cpe:2.3:a:sailpoint:identityiq:8.3:patch5:*:*:*:*:*:* |
|
| First Time |
Sailpoint
Sailpoint identityiq |
|
| References | () https://www.sailpoint.com/security-advisories/sailpoint-identityiq-incorrect-content-type-cross-site-scripting-vulnerability-cve-2025-10280 - Vendor Advisory |
06 Nov 2025, 21:15
| Type | Values Removed | Values Added |
|---|---|---|
| Summary | (en) IdentityIQ 8.5, IdentityIQ 8.4 and all 8.4 patch levels prior to 8.4p4, IdentityIQ 8.3 and all 8.3 patch levels including 8.3p5, and all prior versions allows some IdentityIQ web services that provide non-HTML content to be accessed via a URL path that will set the Content-Type to HTML allowing a requesting browser to interpret content not properly escaped to prevent Cross-Site Scripting (XSS). |
04 Nov 2025, 15:41
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-11-03 17:15
Updated : 2025-11-12 14:49
NVD link : CVE-2025-10280
Mitre link : CVE-2025-10280
CVE.ORG link : CVE-2025-10280
JSON object : View
Products Affected
sailpoint
- identityiq
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
