PT-2024-25140 · Unknown · Identity Security Cloud

Published

2024-05-15

·

Updated

2024-05-15

·

CVE-2024-3317

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Identity Security Cloud (ISC) (affected versions not specified)
Description An issue was found in the Identity Security Cloud (ISC) message server API, related to improper access control. This allowed an authenticated user to access job processing metadata, including opaque messageIDs, work queue depth, and counts, for other tenants.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

CVE-2024-3317

Affected Products

Identity Security Cloud