CVE-2021-38120

Severity CVSS v4.0:
Pending analysis
Type:
CWE-77 Command Injection
Publication date:
28/08/2024
Last modified:
13/09/2024

Description

A vulnerability identified in Advance Authentication that allows bash command Injection in administrative controlled functionality of backup due to improper<br /> handling in provided command parameters. This issue affects NetIQ Advance Authentication version before 6.3.5.1.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:microfocus:netiq_advanced_authentication:*:*:*:*:*:*:*:* 6.3 (excluding)
cpe:2.3:a:microfocus:netiq_advanced_authentication:6.3:-:*:*:*:*:*:*
cpe:2.3:a:microfocus:netiq_advanced_authentication:6.3:sp1:*:*:*:*:*:*
cpe:2.3:a:microfocus:netiq_advanced_authentication:6.3:sp2:*:*:*:*:*:*
cpe:2.3:a:microfocus:netiq_advanced_authentication:6.3:sp3:*:*:*:*:*:*
cpe:2.3:a:microfocus:netiq_advanced_authentication:6.3:sp4:*:*:*:*:*:*
cpe:2.3:a:microfocus:netiq_advanced_authentication:6.3:sp4_patch1:*:*:*:*:*:*
cpe:2.3:a:microfocus:netiq_advanced_authentication:6.3:sp5:*:*:*:*:*:*