IdentityIQ Security Vulnerabilities

IdentityIQ Security Vulnerabilities

This page lists the IdentityIQ major versions and associated patch levels, indicating the applicability and availability of security fixes made generally available. By default, availability of security fixes is based on whether a particular version is in Full, Limited, or Dropped Support status. Refer to the IdentityIQ and SecurityIQ (FAM) End of Life Policy for more information. For versions in Limited Support, only the latest patch level is eligible for future security fixes. Note that versions in Dropped Support are no longer eligible for future security fixes[1].

It's important that security fixes are applied to production environments to safeguard against the vulnerabilities which they resolve. A security fix goes through a development and test cycle that's similar to the process followed when an issue is resolved in an IdentityIQ major version or patch, but is packaged as an e-fix. Each security fix is fully supported through our normal Support channels. When deployed, a reference to the security fix will display in the About page, in the Product Information section under E-Fixes (this UI feature is provided in 7.1p5 & later, 7.2p1 & later, 7.3 and later). If an IdentityIQ version requires multiple security fixes, they can be applied in any order since all security fixes are independent of each other. Each security fix includes a README that provides information on the security vulnerability, as well as installation and verification instructions. Security fixes are rolled into future major versions and patches for versions in Full Support, removing the dependency on the security fix when those future versions are available.

 

 

IdentityIQ 8.2

8.2 GA - 8.2p1

Full Support
Security Fix Release Date Notes
None NA NA

 

IdentityIQ 8.1

8.1p3

Full Support
Security Fix Release Date Notes
IIQETN-9714 May 2021 Affects 8.0 - 8.1 (all patch levels)
IIQSAW-3585 May 2021 Affects 8.0 - 8.1 (all patch levels)
AD PWI v20 [2] January 2020 Password Interceptor for MS Active Directory security fixes
DPR v19 [2] August 2019 Desktop Password Reset security fixes

8.1p1 - 8.1p2

Full Support
Security Fix Release Date Notes
IIQETN-9714 May 2021 Affects 8.0 - 8.1 (all patch levels)
IIQSAW-3585 May 2021 Affects 8.0 - 8.1 (all patch levels)
IIQSAW-3516 March 2021 Affects 7.1 - 8.1 (all patch levels)
AD PWI v20 [2] January 2020 Password Interceptor for MS Active Directory security fixes
DPR v19 [2] August 2019 Desktop Password Reset security fixes

8.1 GA

Full Support
Security Fix Release Date Notes
IIQETN-9714 May 2021 Affects 8.0 - 8.1 (all patch levels)
IIQSAW-3585 May 2021 Affects 8.0 - 8.1 (all patch levels)
IIQSAW-3516 March 2021 Affects 7.1 - 8.1 (all patch levels)
IIQSAW-2905 July 2020 Affects 7.3 GA - 8.1 GA only
AD PWI v20 [2] January 2020 Password Interceptor for MS Active Directory security fixes
DPR v19 [2] August 2019 Desktop Password Reset security fixes

 

IdentityIQ 8.0

8.0p4

Full Support
Security Fix Release Date Notes
IIQETN-9714 May 2021 Affects 8.0 - 8.1 (all patch levels)
IIQSAW-3585 May 2021 Affects 8.0 - 8.1 (all patch levels)
AD PWI v20 [2] January 2020 Password Interceptor for MS Active Directory security fixes
DPR v19 [2] August 2019 Desktop Password Reset security fixes

8.0p3

Full Support
Security Fix Release Date Notes
IIQETN-9714 May 2021 Affects 8.0 - 8.1 (all patch levels)
IIQSAW-3585 May 2021 Affects 8.0 - 8.1 (all patch levels)
IIQSAW-3516 March 2021 Affects 7.1 - 8.1 (all patch levels)
AD PWI v20 [2] January 2020 Password Interceptor for MS Active Directory security fixes
DPR v19 [2] August 2019 Desktop Password Reset security fixes

8.0p2

Full Support
Security Fix Release Date Notes
IIQETN-9714 May 2021 Affects 8.0 - 8.1 (all patch levels)
IIQSAW-3585 May 2021 Affects 8.0 - 8.1 (all patch levels)
IIQSAW-3516 March 2021 Affects 7.1 - 8.1 (all patch levels)
IIQSAW-2905 July 2020 Affects 7.3 GA - 8.1 GA only
AD PWI v20 [2] January 2020 Password Interceptor for MS Active Directory security fixes
DPR v19 [2] August 2019 Desktop Password Reset security fixes

8.0p1

Full Support
Security Fix Release Date Notes
IIQETN-9714 May 2021 Affects 8.0 - 8.1 (all patch levels)
IIQSAW-3585 May 2021 Affects 8.0 - 8.1 (all patch levels)
IIQSAW-3516 March 2021 Affects 7.1 - 8.1 (all patch levels)
IIQSAW-2905 July 2020 Affects 7.3 GA - 8.1 GA only
IIQETN-8680 March 2020 Replaces IIQTC-221 for 7.2 - 7.3
AD PWI v20 [2] January 2020 Password Interceptor for MS Active Directory security fixes
DPR v19 [2] August 2019 Desktop Password Reset security fixes

8.0 GA

Full Support
Security Fix Release Date Notes
IIQETN-9714 May 2021 Affects 8.0 - 8.1 (all patch levels)
IIQSAW-3585 May 2021 Affects 8.0 - 8.1 (all patch levels)
IIQSAW-3516 March 2021 Affects 7.1 - 8.1 (all patch levels)
IIQSAW-2905 July 2020 Affects 7.3 GA - 8.1 GA only
IIQETN-8680 March 2020 Replaces IIQTC-221 for 7.2 - 7.3
AD PWI v20 [2] January 2020 Password Interceptor for MS Active Directory security fixes
DPR v19 [2] August 2019 Desktop Password Reset security fixes
CONETN-2732 July 2019 Mainframe integration security fixes

 

IdentityIQ 7.3

7.3p7

Limited Support
Security Fix Release Date Notes
AD PWI v20 [2] January 2020 Password Interceptor for MS Active Directory security fixes
DPR v19 [2] August 2019 Desktop Password Reset security fixes

7.3p6

Limited Support
Security Fix Release Date Notes
IIQSAW-3516 March 2021 Affects 7.1 - 8.1 (all patch levels)
AD PWI v20 [2] January 2020 Password Interceptor for MS Active Directory security fixes
DPR v19 [2] August 2019 Desktop Password Reset security fixes

7.3p5

Limited Support
Security Fix Release Date Notes
IIQSAW-3516 March 2021 Affects 7.1 - 8.1 (all patch levels)
IIQSAW-2905 July 2020 Affects 7.3 GA - 8.1 GA only
AD PWI v20 [2] January 2020 Password Interceptor for MS Active Directory security fixes
DPR v19 [2] August 2019 Desktop Password Reset security fixes

7.3p3 - 7.3p4

Limited Support
Security Fix Release Date Notes
IIQSAW-3516 March 2021 Affects 7.1 - 8.1 (all patch levels)
IIQSAW-2905 July 2020 Affects 7.3 GA - 8.1 GA only
IIQETN-8680 March 2020 Replaces IIQTC-221 for 7.2 - 7.3
AD PWI v20 [2] January 2020 Password Interceptor for MS Active Directory security fixes
DPR v19 [2] August 2019 Desktop Password Reset security fixes

7.3p2

Limited Support
Security Fix Release Date Notes
IIQSAW-3516 March 2021 Affects 7.1 - 8.1 (all patch levels)
IIQSAW-2905 July 2020 Affects 7.3 GA - 8.1 GA only
IIQETN-8680 March 2020 Replaces IIQTC-221 for 7.2 - 7.3
AD PWI v20 [2] January 2020 Password Interceptor for MS Active Directory security fixes
DPR v19 [2] August 2019 Desktop Password Reset security fixes
CONETN-2732 July 2019 Mainframe integration security fixes
IIQSR-148 April 2019 Replaces IIQTC-118 for 7.0p9, 7.1 - 7.3
IIQETN-7708 April 2019  
CONETN-2645 April 2019 IQService security fixes

7.3 GA - 7.3p1

Limited Support
Security Fix Release Date Notes
IIQSAW-3516 March 2021 Affects 7.1 - 8.1 (all patch levels)
IIQSAW-2905 July 2020 Affects 7.3 GA - 8.1 GA only
IIQETN-8680 March 2020 Replaces IIQTC-221 for 7.2 - 7.3
AD PWI v20 [2] January 2020 Password Interceptor for MS Active Directory security fixes
DPR v19 [2] August 2019 Desktop Password Reset security fixes
CONETN-2732 July 2019 Mainframe integration security fixes
IIQSR-148 April 2019 Replaces IIQTC-118 for 7.0p9, 7.1 - 7.3
IIQETN-7708 April 2019  
CONETN-2645 April 2019 IQService security fixes
IIQETN-7523 February 2019 Replaces IIQETN-7058 for all versions

 

IdentityIQ 7.2 

7.2p6

Limited Support
Security Fix Release Date Notes
IIQSAW-3516 March 2021 Affects 7.1 - 8.1 (all patch levels)
AD PWI v20 [2] January 2020 Password Interceptor for MS Active Directory security fixes
DPR v19 [2] August 2019 Desktop Password Reset security fixes

 

7.2p5

Limited Support
Security Fix Release Date Notes
AD PWI v20 [2] January 2020 Password Interceptor for MS Active Directory security fixes
DPR v19 [2] August 2019 Desktop Password Reset security fixes

7.2p4

Limited Support
Security Fix Release Date Notes
IIQETN-8680 March 2020 Replaces IIQTC-221 for 7.2 - 7.3
AD PWI v20 [2] January 2020 Password Interceptor for MS Active Directory security fixes
DPR v19 [2] August 2019 Desktop Password Reset security fixes
CONETN-2732 July 2019 Mainframe integration security fixes

7.2p1 - 7.2p3

Limited Support
Security Fix Release Date Notes
IIQETN-8680 March 2020 Replaces IIQTC-221 for 7.2 - 7.3
AD PWI v20 [2] January 2020 Password Interceptor for MS Active Directory security fixes
DPR v19 [2] August 2019 Desktop Password Reset security fixes
CONETN-2732 July 2019 Mainframe integration security fixes
IIQSR-148 April 2019 Replaces IIQTC-118 for 7.0p9, 7.1 - 7.3
IIQETN-7708 April 2019  
CONETN-2645 April 2019 IQService security fixes
IIQETN-7523 February 2019 Replaces IIQETN-7058 for all versions

7.2 GA

Limited Support
Security Fix Release Date Notes
IIQETN-8680 March 2020 Replaces IIQTC-221 for 7.2 - 7.3
AD PWI v20 [2] January 2020 Password Interceptor for MS Active Directory security fixes
DPR v19 [2] August 2019 Desktop Password Reset security fixes
CONETN-2732 July 2019 Mainframe integration security fixes
IIQSR-148 April 2019 Replaces IIQTC-118 for 7.0p9, 7.1 - 7.3
IIQETN-7708 April 2019  
CONETN-2645 April 2019 IQService security fixes
IIQETN-7523 February 2019 Replaces IIQETN-7058 for all versions
IIQETN-6320 January 2018  

 

IdentityIQ 7.1

7.1p7

Dropped Support
Security Fix Release Date Notes
IIQSAW-3516 March 2021 Affects 7.1 - 8.1 (all patch levels)
IIQETN-8680 March 2020 Replaces IIQTC-221 for 7.2 - 7.3
AD PWI v20 [2] January 2020 Password Interceptor for MS Active Directory security fixes
DPR v19 [2] August 2019 Desktop Password Reset security fixes

7.1p6

Dropped Support
Security Fix Release Date Notes
AD PWI v20 [2] January 2020 Password Interceptor for MS Active Directory security fixes
IIQTC-221 September 2019 Superseded by IIQETN-8680 for 7.2 - 7.3
DPR v19 [2] August 2019 Desktop Password Reset security fixes
CONETN-2732 July 2019 Mainframe integration security fixes
CONETN-2645 April 2019 IQService security fixes

7.1p5

Dropped Support
Security Fix Release Date Notes
AD PWI v20 [2] January 2020 Password Interceptor for MS Active Directory security fixes
IIQTC-221 September 2019 Superseded by IIQETN-8680 for 7.2 - 7.3
DPR v19 [2] August 2019 Desktop Password Reset security fixes
CONETN-2732 July 2019 Mainframe integration security fixes
IIQSR-148 April 2019 Replaces IIQTC-118 for 7.0p9, 7.1 - 7.3
IIQETN-7708 April 2019  
CONETN-2645 April 2019 IQService security fixes
IIQETN-7523 February 2019 Replaces IIQETN-7058 for all versions

7.1p4

Dropped Support
Security Fix Release Date Notes
AD PWI v20 [2] January 2020 Password Interceptor for MS Active Directory security fixes
IIQTC-221 September 2019 Superseded by IIQETN-8680 for 7.2 - 7.3
DPR v19 [2] August 2019 Desktop Password Reset security fixes
CONETN-2732 July 2019 Mainframe integration security fixes
IIQSR-148 April 2019 Replaces IIQTC-118 for 7.0p9, 7.1 - 7.3
IIQETN-7708 April 2019  
CONETN-2645 April 2019 IQService security fixes
IIQETN-7523 February 2019 Replaces IIQETN-7058 for all versions
IIQETN-6320 January 2018  

7.1p3

Dropped Support
Security Fix Release Date Notes
AD PWI v20 [2] January 2020 Password Interceptor for MS Active Directory security fixes
IIQTC-221 September 2019 Superseded by IIQETN-8680 for 7.2 - 7.3
DPR v19 [2] August 2019 Desktop Password Reset security fixes
CONETN-2732 July 2019 Mainframe integration security fixes
IIQSR-148 April 2019 Replaces IIQTC-118 for 7.0p9, 7.1 - 7.3
IIQETN-7708 April 2019  
CONETN-2645 April 2019 IQService security fixes
IIQETN-7523 February 2019 Replaces IIQETN-7058 for all versions
IIQETN-6320 January 2018  

7.1p2

Dropped Support
Security Fix Release Date Notes
AD PWI v20 [2] January 2020 Password Interceptor for MS Active Directory security fixes
IIQTC-221 September 2019 Superseded by IIQETN-8680 for 7.2 - 7.3
DPR v19 [2] August 2019 Desktop Password Reset security fixes
CONETN-2732 July 2019 Mainframe integration security fixes
IIQSR-148 April 2019 Replaces IIQTC-118 for 7.0p9, 7.1 - 7.3
IIQETN-7708 April 2019  
CONETN-2645 April 2019 IQService security fixes
IIQETN-7523 February 2019 Replaces IIQETN-7058 for all versions
IIQETN-6320 January 2018  
IIQETN-5494 August 2017  

7.1 GA - 7.1p1

Dropped Support
Security Fix Release Date Notes
AD PWI v20 [2] January 2020 Password Interceptor for MS Active Directory security fixes
IIQTC-221 September 2019 Superseded by IIQETN-8680 for 7.2 - 7.3
DPR v19 [2] August 2019 Desktop Password Reset security fixes
CONETN-2732 July 2019 Mainframe integration security fixes
IIQSR-148 April 2019 Replaces IIQTC-118 for 7.0p9, 7.1 - 7.3
IIQETN-7708 April 2019  
CONETN-2645 April 2019 IQService security fixes
IIQETN-7523 February 2019 Replaces IIQETN-7058 for all versions
IIQETN-6320 January 2018  
IIQETN-5494 August 2017  
IIQETN-5402 July 2017  

 

Footnotes

  1. SailPoint may initiate, at its discretion, an exception to this policy in order to resolve a critical security vulnerability for an IdentityIQ version in Dropped Support.
  2. SailPoint Desktop Password Reset (DPR) and Password Interceptor for MS Active Directory (AD PWI) are ancillary components and have no dependency on IdentityIQ version. If either is being used in your environment, the specified version (or later) is recommended to resolve a high severity vulnerability. Note that these deliverables are not packaged as a typical security e-fix, but are full version updates.
Version history
Revision #:
67 of 67
Last update:
‎Sep 28, 2021 06:18 PM
Updated by: