PT-2024-39905 · Okta · Okta Privileged Access Server Agent

Published

2024-11-20

·

Updated

2024-11-21

·

CVE-2024-9875

CVSS v3.1

7.1

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Okta Privileged Access server agent (SFTD) versions 1.82.0 through 1.84.0
Description The issue is related to a privilege escalation vulnerability when the sudo command bundles feature is enabled.
Recommendations For Okta Privileged Access server agent (SFTD) versions 1.82.0 through 1.84.0, upgrade to version 1.87.1 or greater to remediate the vulnerability.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-9875

Affected Products

Okta Privileged Access Server Agent