CVE-2024-56404: Oneidentity Identity Manager
Critical severity, CVSS 9.9. EPSS: 0.7% chance of exploitation in the next 30 days.
In One Identity Identity Manager 9.x before 9.3, an insecure direct object reference (IDOR) vulnerability allows privilege escalation. Only On-Premise installations are affected.
Affected products
- Oneidentity Identity Manager: from 9.0.0, before 9.3 (fixed in 9.3)
Published 2025-01-24. Last modified 2026-06-17.