3.9
CVE-2022-1697
- EPSS 0.07%
- Veröffentlicht 06.09.2022 18:15:10
- Zuletzt bearbeitet 21.11.2024 06:41:16
- Quelle psirt@okta.com
- CVE-Watchlists
- Unerledigt
Okta Active Directory Agent versions 3.8.0 through 3.11.0 installed the Okta AD Agent Update Service using an unquoted path. Note: To remediate this vulnerability, you must uninstall Okta Active Directory Agent and reinstall Okta Active Directory Agent 3.12.0 or greater per the documentation.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Okta ≫ Active Directory Agent Version3.8.0
Okta ≫ Active Directory Agent Version3.9.0
Okta ≫ Active Directory Agent Version3.10.0
Okta ≫ Active Directory Agent Version3.11.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.07% | 0.215 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 3.9 | 0.5 | 3.4 |
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:L
|
CWE-428 Unquoted Search Path or Element
The product uses a search path that contains an unquoted element, in which the element contains whitespace or other separators. This can cause the product to access resources in a parent path.