扬帆起航:SailPoint IQService 默认加密密钥引发的远程代码执行漏洞
netspi.com | 漏洞 | #rce | #encryption | #default-credentials | #iam | #sailpoint | #iqservice | #network-pentesting
摘要
SailPoint IQService 在 2025 年 5 月更新前以默认配置部署时存在 RCE 风险:其 RPC 服务使用硬编码加密密钥且无身份认证与 TLS,掌握默认密钥的攻击者可发送构造请求执行任意代码。
- 发布时间
- 收录时间
Skip to content