Lucene search

K
nvd[email protected]NVD:CVE-2022-1697
HistorySep 06, 2022 - 6:15 p.m.

CVE-2022-1697

2022-09-0618:15:10
CWE-428
web.nvd.nist.gov
3
okta
active directory
unquoted path

CVSS3

3.9

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:L

EPSS

0.001

Percentile

34.4%

Okta Active Directory Agent versions 3.8.0 through 3.11.0 installed the Okta AD Agent Update Service using an unquoted path. Note: To remediate this vulnerability, you must uninstall Okta Active Directory Agent and reinstall Okta Active Directory Agent 3.12.0 or greater per the documentation.

Affected configurations

Nvd
Node
oktaactive_directory_agentMatch3.8.0
OR
oktaactive_directory_agentMatch3.9.0
OR
oktaactive_directory_agentMatch3.10.0
OR
oktaactive_directory_agentMatch3.11.0
VendorProductVersionCPE
oktaactive_directory_agent3.8.0cpe:2.3:a:okta:active_directory_agent:3.8.0:*:*:*:*:*:*:*
oktaactive_directory_agent3.9.0cpe:2.3:a:okta:active_directory_agent:3.9.0:*:*:*:*:*:*:*
oktaactive_directory_agent3.10.0cpe:2.3:a:okta:active_directory_agent:3.10.0:*:*:*:*:*:*:*
oktaactive_directory_agent3.11.0cpe:2.3:a:okta:active_directory_agent:3.11.0:*:*:*:*:*:*:*

CVSS3

3.9

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:L

EPSS

0.001

Percentile

34.4%

Related for NVD:CVE-2022-1697