PT-2024-10988 · Netiq · Netiq Advance Authentication

Published

2024-08-27

·

Updated

2024-09-13

·

CVE-2021-38120

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions NetIQ Advance Authentication versions prior to 6.3.5.1
Description A vulnerability identified in Advance Authentication allows bash command injection in administrative controlled functionality of backup due to improper handling in provided command parameters.
Recommendations For versions prior to 6.3.5.1, update to version 6.3.5.1 to protect against exploitation. As a temporary workaround, consider restricting access to the administrative controlled functionality of backup until a patch is available. Avoid using the affected functionality in the backup process until the issue is resolved.

Fix

Command Injection

Weakness Enumeration

Related Identifiers

CVE-2021-38120

Affected Products

Netiq Advance Authentication