IdentityIQ Security Vulnerabilities

IdentityIQ Security Vulnerabilities

This page lists the IdentityIQ major versions and associated patch levels, indicating the applicability and availability of security fixes made generally available. By default, availability of security fixes is based on whether a particular version is in Full, Limited, or Dropped Support status. Refer to the IdentityIQ and File Access Manager End of Life Policy for more information. For versions in Limited Support, only the latest patch level is eligible for future security fixes. Note that versions in Dropped Support are no longer eligible for future security fixes[1].

It's important that security fixes are applied to production environments to safeguard against the vulnerabilities which they resolve. A security fix goes through a development and test cycle that's similar to the process followed when an issue is resolved in an IdentityIQ major version or patch, but is packaged as an e-fix. Each security fix is fully supported through our normal Support channels. When deployed, a reference to the security fix will display in the About page, in the Product Information section under E-Fixes. If an IdentityIQ version requires multiple security fixes, they can be applied in any order since all security fixes are independent of each other. Each security fix includes a README that provides information on the security vulnerability, as well as installation and verification instructions. Security fixes are rolled into future major versions and patches for versions in Full Support, removing the dependency on the security fix when those future versions are available.

 

 

IdentityIQ 8.3

8.3 GA - 8.3p1

Full Support
Security Fix Release Date Notes
DPR v19 [2] Mar 2022 Desktop Password Reset security fixes

 

IdentityIQ 8.2

8.2p2 - 8.2p4

Full Support
Security Fix Release Date Notes
DPR v19 [2] Mar 2022 Desktop Password Reset security fixes

8.2 GA - 8.2p1

Full Support
Security Fix Release Date Notes
DPR v19 [2] Mar 2022 Desktop Password Reset security fixes
IIQCB-4610 Jan 2022 Affects 8.0 - 8.2 (all patch levels)
IIQPB-1066 Jan 2022 Affects 7.2 - 8.2 (all patch levels)
IIQCB-4601 Dec 2021 Superseded by IIQCB-4610
IIQPB-1008 Nov 2021 Affects 7.2 - 8.2 (all patch levels)
AD PWI v20 [2] Jan 2020 Password Interceptor for MS Active Directory security fixes

 

IdentityIQ 8.1

8.1p5 - 8.1p6

Full Support
Security Fix Release Date Notes
DPR v19 [2] Mar 2022 Desktop Password Reset security fixes
AD PWI v20 [2] Jan 2020 Password Interceptor for MS Active Directory security fixes

8.1p4

Full Support
Security Fix Release Date Notes
DPR v19 [2] Mar 2022 Desktop Password Reset security fixes
IIQCB-4610 Jan 2022 Affects 8.0 - 8.2 (all patch levels)
IIQPB-1066 Jan 2022 Affects 7.2 - 8.2 (all patch levels)
AD PWI v20 [2] Jan 2020 Password Interceptor for MS Active Directory security fixes

8.1p3

Full Support
Security Fix Release Date Notes
DPR v19 [2] Mar 2022 Desktop Password Reset security fixes
IIQCB-4610 Jan 2022 Affects 8.0 - 8.2 (all patch levels)
IIQPB-1066 Jan 2022 Affects 7.2 - 8.2 (all patch levels)
IIQCB-4601 Dec 2021 Superseded by IIQCB-4610
IIQPB-1008 Nov 2021 Affects 7.2 - 8.2 (all patch levels)
IIQETN-9714 May 2021 Affects 8.0 - 8.1 (all patch levels)
IIQSAW-3585 May 2021 Affects 8.0 - 8.1 (all patch levels)
AD PWI v20 [2] Jan 2020 Password Interceptor for MS Active Directory security fixes

8.1p1 - 8.1p2

Full Support
Security Fix Release Date Notes
DPR v19 [2] Mar 2022 Desktop Password Reset security fixes
IIQCB-4610 Jan 2022 Affects 8.0 - 8.2 (all patch levels)
IIQPB-1066 Jan 2022 Affects 7.2 - 8.2 (all patch levels)
IIQCB-4601 Dec 2021 Superseded by IIQCB-4610
IIQPB-1008 Nov 2021 Affects 7.2 - 8.2 (all patch levels)
IIQETN-9714 May 2021 Affects 8.0 - 8.1 (all patch levels)
IIQSAW-3585 May 2021 Affects 8.0 - 8.1 (all patch levels)
IIQSAW-3516 Mar 2021 Affects 7.1 - 8.1 (all patch levels)
AD PWI v20 [2] Jan 2020 Password Interceptor for MS Active Directory security fixes

8.1 GA

Full Support
Security Fix Release Date Notes
DPR v19 [2] Mar 2022 Desktop Password Reset security fixes
IIQCB-4610 Jan 2022 Affects 8.0 - 8.2 (all patch levels)
IIQPB-1066 Jan 2022 Affects 7.2 - 8.2 (all patch levels)
IIQCB-4601 Dec 2021 Superseded by IIQCB-4610
IIQPB-1008 Nov 2021 Affects 7.2 - 8.2 (all patch levels)
IIQETN-9714 May 2021 Affects 8.0 - 8.1 (all patch levels)
IIQSAW-3585 May 2021 Affects 8.0 - 8.1 (all patch levels)
IIQSAW-3516 Mar 2021 Affects 7.1 - 8.1 (all patch levels)
IIQSAW-2905 Jul 2020 Affects 7.3 GA - 8.1 GA only
AD PWI v20 [2] Jan 2020 Password Interceptor for MS Active Directory security fixes

 

IdentityIQ 8.0

8.0p5

Limited Support
Security Fix Release Date Notes
DPR v19 [2] Mar 2022 Desktop Password Reset security fixes
IIQCB-4610 Jan 2022 Affects 8.0 - 8.2 (all patch levels)
IIQPB-1066 Jan 2022 Affects 7.2 - 8.2 (all patch levels)
IIQCB-4601 Dec 2021 Superseded by IIQCB-4610
AD PWI v20 [2] Jan 2020 Password Interceptor for MS Active Directory security fixes

8.0p4

Limited Support
Security Fix Release Date Notes
DPR v19 [2] Mar 2022 Desktop Password Reset security fixes
IIQCB-4610 Jan 2022 Affects 8.0 - 8.2 (all patch levels)
IIQPB-1066 Jan 2022 Affects 7.2 - 8.2 (all patch levels)
IIQCB-4601 Dec 2021 Superseded by IIQCB-4610
IIQPB-1008 Nov 2021 Affects 7.2 - 8.2 (all patch levels)
IIQETN-9714 May 2021 Affects 8.0 - 8.1 (all patch levels)
IIQSAW-3585 May 2021 Affects 8.0 - 8.1 (all patch levels)
AD PWI v20 [2] Jan 2020 Password Interceptor for MS Active Directory security fixes

8.0p3

Limited Support
Security Fix Release Date Notes
DPR v19 [2] Mar 2022 Desktop Password Reset security fixes
IIQCB-4610 Jan 2022 Affects 8.0 - 8.2 (all patch levels)
IIQPB-1066 Jan 2022 Affects 7.2 - 8.2 (all patch levels)
IIQCB-4601 Dec 2021 Superseded by IIQCB-4610
IIQPB-1008 Nov 2021 Affects 7.2 - 8.2 (all patch levels)
IIQETN-9714 May 2021 Affects 8.0 - 8.1 (all patch levels)
IIQSAW-3585 May 2021 Affects 8.0 - 8.1 (all patch levels)
IIQSAW-3516 Mar 2021 Affects 7.1 - 8.1 (all patch levels)
AD PWI v20 [2] Jan 2020 Password Interceptor for MS Active Directory security fixes

8.0p2

Limited Support
Security Fix Release Date Notes
DPR v19 [2] Mar 2022 Desktop Password Reset security fixes
IIQCB-4610 Jan 2022 Affects 8.0 - 8.2 (all patch levels)
IIQPB-1066 Jan 2022 Affects 7.2 - 8.2 (all patch levels)
IIQCB-4601 Dec 2021 Superseded by IIQCB-4610
IIQPB-1008 Nov 2021 Affects 7.2 - 8.2 (all patch levels)
IIQETN-9714 May 2021 Affects 8.0 - 8.1 (all patch levels)
IIQSAW-3585 May 2021 Affects 8.0 - 8.1 (all patch levels)
IIQSAW-3516 Mar 2021 Affects 7.1 - 8.1 (all patch levels)
IIQSAW-2905 Jul 2020 Affects 7.3 GA - 8.1 GA only
AD PWI v20 [2] Jan 2020 Password Interceptor for MS Active Directory security fixes

8.0p1

Limited Support
Security Fix Release Date Notes
DPR v19 [2] Mar 2022 Desktop Password Reset security fixes
IIQCB-4610 Jan 2022 Affects 8.0 - 8.2 (all patch levels)
IIQPB-1066 Jan 2022 Affects 7.2 - 8.2 (all patch levels)
IIQCB-4601 Dec 2021 Superseded by IIQCB-4610
IIQPB-1008 Nov 2021 Affects 7.2 - 8.2 (all patch levels)
IIQETN-9714 May 2021 Affects 8.0 - 8.1 (all patch levels)
IIQSAW-3585 May 2021 Affects 8.0 - 8.1 (all patch levels)
IIQSAW-3516 Mar 2021 Affects 7.1 - 8.1 (all patch levels)
IIQSAW-2905 Jul 2020 Affects 7.3 GA - 8.1 GA only
IIQETN-8680 Mar 2020 Replaces IIQTC-221 for 7.2 - 7.3
AD PWI v20 [2] Jan 2020 Password Interceptor for MS Active Directory security fixes

8.0 GA

Limited Support
Security Fix Release Date Notes
DPR v19 [2] Mar 2022 Desktop Password Reset security fixes
IIQCB-4610 Jan 2022 Affects 8.0 - 8.2 (all patch levels)
IIQPB-1066 Jan 2022 Affects 7.2 - 8.2 (all patch levels)
IIQCB-4601 Dec 2021 Superseded by IIQCB-4610
IIQPB-1008 Nov 2021 Affects 7.2 - 8.2 (all patch levels)
IIQETN-9714 May 2021 Affects 8.0 - 8.1 (all patch levels)
IIQSAW-3585 May 2021 Affects 8.0 - 8.1 (all patch levels)
IIQSAW-3516 Mar 2021 Affects 7.1 - 8.1 (all patch levels)
IIQSAW-2905 Jul 2020 Affects 7.3 GA - 8.1 GA only
IIQETN-8680 Mar 2020 Replaces IIQTC-221 for 7.2 - 7.3
AD PWI v20 [2] Jan 2020 Password Interceptor for MS Active Directory security fixes
CONETN-2732 Jul 2019 Mainframe integration security fixes

 

IdentityIQ 7.3

7.3p7

Dropped Support
Security Fix Release Date Notes
DPR v19 [2] Mar 2022 Desktop Password Reset security fixes
IIQPB-1066 Jan 2022 Affects 7.2 - 8.2 (all patch levels)
IIQPB-1008 Nov 2021 Affects 7.2 - 8.2 (all patch levels)
AD PWI v20 [2] Jan 2020 Password Interceptor for MS Active Directory security fixes

7.3p6

Dropped Support
Security Fix Release Date Notes
DPR v19 [2] Mar 2022 Desktop Password Reset security fixes
IIQSAW-3516 Mar 2021 Affects 7.1 - 8.1 (all patch levels)
AD PWI v20 [2] Jan 2020 Password Interceptor for MS Active Directory security fixes

7.3p5

Dropped Support
Security Fix Release Date Notes
DPR v19 [2] Mar 2022 Desktop Password Reset security fixes
IIQSAW-3516 Mar 2021 Affects 7.1 - 8.1 (all patch levels)
IIQSAW-2905 Jul 2020 Affects 7.3 GA - 8.1 GA only
AD PWI v20 [2] Jan 2020 Password Interceptor for MS Active Directory security fixes

7.3p3 - 7.3p4

Dropped Support
Security Fix Release Date Notes
DPR v19 [2] Mar 2022 Desktop Password Reset security fixes
IIQSAW-3516 Mar 2021 Affects 7.1 - 8.1 (all patch levels)
IIQSAW-2905 Jul 2020 Affects 7.3 GA - 8.1 GA only
IIQETN-8680 Mar 2020 Replaces IIQTC-221 for 7.2 - 7.3
AD PWI v20 [2] Jan 2020 Password Interceptor for MS Active Directory security fixes

7.3p2

Dropped Support
Security Fix Release Date Notes
DPR v19 [2] Mar 2022 Desktop Password Reset security fixes
IIQSAW-3516 Mar 2021 Affects 7.1 - 8.1 (all patch levels)
IIQSAW-2905 Jul 2020 Affects 7.3 GA - 8.1 GA only
IIQETN-8680 Mar 2020 Replaces IIQTC-221 for 7.2 - 7.3
AD PWI v20 [2] Jan 2020 Password Interceptor for MS Active Directory security fixes
CONETN-2732 Jul 2019 Mainframe integration security fixes
IIQSR-148 Apr 2019 Replaces IIQTC-118 for 7.0p9, 7.1 - 7.3
IIQETN-7708 Apr 2019  
CONETN-2645 Apr 2019 IQService security fixes

7.3 GA - 7.3p1

Dropped Support
Security Fix Release Date Notes
DPR v19 [2] Mar 2022 Desktop Password Reset security fixes
IIQSAW-3516 Mar 2021 Affects 7.1 - 8.1 (all patch levels)
IIQSAW-2905 Jul 2020 Affects 7.3 GA - 8.1 GA only
IIQETN-8680 Mar 2020 Replaces IIQTC-221 for 7.2 - 7.3
AD PWI v20 [2] Jan 2020 Password Interceptor for MS Active Directory security fixes
CONETN-2732 Jul 2019 Mainframe integration security fixes
IIQSR-148 Apr 2019 Replaces IIQTC-118 for 7.0p9, 7.1 - 7.3
IIQETN-7708 Apr 2019  
CONETN-2645 Apr 2019 IQService security fixes
IIQETN-7523 Feb 2019 Replaces IIQETN-7058 for all versions

 

IdentityIQ 7.2 

7.2p6

Dropped Support
Security Fix Release Date Notes
DPR v19 [2] Mar 2022 Desktop Password Reset security fixes
IIQPB-1066 Jan 2022 Affects 7.2 - 8.2 (all patch levels)
IIQPB-1008 Nov 2021 Affects 7.2 - 8.2 (all patch levels)
IIQSAW-3516 Mar 2021 Affects 7.1 - 8.1 (all patch levels)
AD PWI v20 [2] Jan 2020 Password Interceptor for MS Active Directory security fixes

 

7.2p5

Dropped Support
Security Fix Release Date Notes
DPR v19 [2] Mar 2022 Desktop Password Reset security fixes
AD PWI v20 [2] Jan 2020 Password Interceptor for MS Active Directory security fixes

7.2p4

Dropped Support
Security Fix Release Date Notes
DPR v19 [2] Mar 2022 Desktop Password Reset security fixes
IIQETN-8680 Mar 2020 Replaces IIQTC-221 for 7.2 - 7.3
AD PWI v20 [2] Jan 2020 Password Interceptor for MS Active Directory security fixes
CONETN-2732 Jul 2019 Mainframe integration security fixes

7.2p1 - 7.2p3

Dropped Support
Security Fix Release Date Notes
DPR v19 [2] Mar 2022 Desktop Password Reset security fixes
IIQETN-8680 Mar 2020 Replaces IIQTC-221 for 7.2 - 7.3
AD PWI v20 [2] Jan 2020 Password Interceptor for MS Active Directory security fixes
CONETN-2732 Jul 2019 Mainframe integration security fixes
IIQSR-148 Apr 2019 Replaces IIQTC-118 for 7.0p9, 7.1 - 7.3
IIQETN-7708 Apr 2019  
CONETN-2645 Apr 2019 IQService security fixes
IIQETN-7523 Feb 2019 Replaces IIQETN-7058 for all versions

7.2 GA

Dropped Support
Security Fix Release Date Notes
DPR v19 [2] Mar 2022 Desktop Password Reset security fixes
IIQETN-8680 Mar 2020 Replaces IIQTC-221 for 7.2 - 7.3
AD PWI v20 [2] Jan 2020 Password Interceptor for MS Active Directory security fixes
CONETN-2732 Jul 2019 Mainframe integration security fixes
IIQSR-148 Apr 2019 Replaces IIQTC-118 for 7.0p9, 7.1 - 7.3
IIQETN-7708 Apr 2019  
CONETN-2645 Apr 2019 IQService security fixes
IIQETN-7523 Feb 2019 Replaces IIQETN-7058 for all versions
IIQETN-6320 Jan 2018  

 

IdentityIQ 7.1

7.1p7

Dropped Support
Security Fix Release Date Notes
IIQSAW-3516 March 2021 Affects 7.1 - 8.1 (all patch levels)
IIQETN-8680 March 2020 Replaces IIQTC-221 for 7.2 - 7.3
AD PWI v20 [2] January 2020 Password Interceptor for MS Active Directory security fixes
DPR v19 [2] August 2019 Desktop Password Reset security fixes

7.1p6

Dropped Support
Security Fix Release Date Notes
AD PWI v20 [2] January 2020 Password Interceptor for MS Active Directory security fixes
IIQTC-221 September 2019 Superseded by IIQETN-8680 for 7.2 - 7.3
DPR v19 [2] August 2019 Desktop Password Reset security fixes
CONETN-2732 July 2019 Mainframe integration security fixes
CONETN-2645 April 2019 IQService security fixes

7.1p5

Dropped Support
Security Fix Release Date Notes
AD PWI v20 [2] January 2020 Password Interceptor for MS Active Directory security fixes
IIQTC-221 September 2019 Superseded by IIQETN-8680 for 7.2 - 7.3
DPR v19 [2] August 2019 Desktop Password Reset security fixes
CONETN-2732 July 2019 Mainframe integration security fixes
IIQSR-148 April 2019 Replaces IIQTC-118 for 7.0p9, 7.1 - 7.3
IIQETN-7708 April 2019  
CONETN-2645 April 2019 IQService security fixes
IIQETN-7523 February 2019 Replaces IIQETN-7058 for all versions

7.1p4

Dropped Support
Security Fix Release Date Notes
AD PWI v20 [2] January 2020 Password Interceptor for MS Active Directory security fixes
IIQTC-221 September 2019 Superseded by IIQETN-8680 for 7.2 - 7.3
DPR v19 [2] August 2019 Desktop Password Reset security fixes
CONETN-2732 July 2019 Mainframe integration security fixes
IIQSR-148 April 2019 Replaces IIQTC-118 for 7.0p9, 7.1 - 7.3
IIQETN-7708 April 2019  
CONETN-2645 April 2019 IQService security fixes
IIQETN-7523 February 2019 Replaces IIQETN-7058 for all versions
IIQETN-6320 January 2018  

7.1p3

Dropped Support
Security Fix Release Date Notes
AD PWI v20 [2] January 2020 Password Interceptor for MS Active Directory security fixes
IIQTC-221 September 2019 Superseded by IIQETN-8680 for 7.2 - 7.3
DPR v19 [2] August 2019 Desktop Password Reset security fixes
CONETN-2732 July 2019 Mainframe integration security fixes
IIQSR-148 April 2019 Replaces IIQTC-118 for 7.0p9, 7.1 - 7.3
IIQETN-7708 April 2019  
CONETN-2645 April 2019 IQService security fixes
IIQETN-7523 February 2019 Replaces IIQETN-7058 for all versions
IIQETN-6320 January 2018  

7.1p2

Dropped Support
Security Fix Release Date Notes
AD PWI v20 [2] January 2020 Password Interceptor for MS Active Directory security fixes
IIQTC-221 September 2019 Superseded by IIQETN-8680 for 7.2 - 7.3
DPR v19 [2] August 2019 Desktop Password Reset security fixes
CONETN-2732 July 2019 Mainframe integration security fixes
IIQSR-148 April 2019 Replaces IIQTC-118 for 7.0p9, 7.1 - 7.3
IIQETN-7708 April 2019  
CONETN-2645 April 2019 IQService security fixes
IIQETN-7523 February 2019 Replaces IIQETN-7058 for all versions
IIQETN-6320 January 2018  
IIQETN-5494 August 2017  

7.1 GA - 7.1p1

Dropped Support
Security Fix Release Date Notes
AD PWI v20 [2] January 2020 Password Interceptor for MS Active Directory security fixes
IIQTC-221 September 2019 Superseded by IIQETN-8680 for 7.2 - 7.3
DPR v19 [2] August 2019 Desktop Password Reset security fixes
CONETN-2732 July 2019 Mainframe integration security fixes
IIQSR-148 April 2019 Replaces IIQTC-118 for 7.0p9, 7.1 - 7.3
IIQETN-7708 April 2019  
CONETN-2645 April 2019 IQService security fixes
IIQETN-7523 February 2019 Replaces IIQETN-7058 for all versions
IIQETN-6320 January 2018  
IIQETN-5494 August 2017  
IIQETN-5402 July 2017  

 

Footnotes

  1. SailPoint may initiate, at its discretion, an exception to this policy in order to resolve a critical security vulnerability for an IdentityIQ version in Dropped Support.
  2. SailPoint Desktop Password Reset (DPR) and Password Interceptor for MS Active Directory (AD PWI) are ancillary components and have no dependency on IdentityIQ version. If either is being used in your environment, the specified version (or later) is recommended to resolve a high severity vulnerability. Note that these deliverables are not packaged as a typical security e-fix, but are full version updates.
Version history
Revision #:
92 of 92
Last update:
‎Nov 16, 2022 06:16 PM
Updated by: