CVE-2022-1697

CVSS V2 None CVSS V3 Low 3.9
Description
Okta Active Directory Agent versions 3.8.0 through 3.11.0 installed the Okta AD Agent Update Service using an unquoted path. Note: To remediate this vulnerability, you must uninstall Okta Active Directory Agent and reinstall Okta Active Directory Agent 3.12.0 or greater per the documentation.
Overview
  • CVE ID
  • CVE-2022-1697
  • Assigner
  • psirt@okta.com
  • Vulnerability Status
  • Analyzed
  • Published Version
  • 2022-09-06T18:15:10
  • Last Modified Date
  • 2022-09-16T16:25:29
CPE Configuration (Product)
CPE Vulnerable Operator Version Start Version End
cpe:2.3:a:okta:active_directory_agent:3.8.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:okta:active_directory_agent:3.9.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:okta:active_directory_agent:3.10.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:okta:active_directory_agent:3.11.0:*:*:*:*:*:*:* 1 OR
CVSS Version 3
  • Version
  • 3.1
  • Vector String
  • CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:L
  • Attack Vector
  • LOCAL
  • Attack Compatibility
  • HIGH
  • Privileges Required
  • HIGH
  • User Interaction
  • NONE
  • Scope
  • UNCHANGED
  • Confidentiality Impact
  • LOW
  • Availability Impact
  • LOW
  • Base Score
  • 3.9
  • Base Severity
  • LOW
  • Exploitability Score
  • 0.5
  • Impact Score
  • 3.4
History
Created Old Value New Value Data Type Notes
2022-09-06 19:00:10 Added to TrackCVE