PT-2022-16587 · Okta · Okta Advanced Server Access Client

Andreas Lindh

·

Published

2022-02-21

·

Updated

2023-08-08

·

CVE-2022-24295

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Okta Advanced Server Access Client for Windows versions prior to 1.57.0
Description The issue is related to command injection via a specially crafted URL.
Recommendations For versions prior to 1.57.0, update to version 1.57.0 or later to resolve the issue.

Fix

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2022-24295

Affected Products

Okta Advanced Server Access Client