PT-2024-10988 · Netiq · Netiq Advance Authentication
Published
2024-08-27
·
Updated
2024-09-13
·
CVE-2021-38120
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
NetIQ Advance Authentication versions prior to 6.3.5.1
Description
A vulnerability identified in Advance Authentication allows bash command injection in administrative controlled functionality of backup due to improper handling in provided command parameters.
Recommendations
For versions prior to 6.3.5.1, update to version 6.3.5.1 to protect against exploitation.
As a temporary workaround, consider restricting access to the administrative controlled functionality of backup until a patch is available.
Avoid using the affected functionality in the backup process until the issue is resolved.
Fix
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Netiq Advance Authentication