CVE-2022-1697

Severity CVSS v4.0:
Pending analysis
Type:
CWE-428 Unquoted Search Path or Element
Publication date:
06/09/2022
Last modified:
16/09/2022

Description

Okta Active Directory Agent versions 3.8.0 through 3.11.0 installed the Okta AD Agent Update Service using an unquoted path. Note: To remediate this vulnerability, you must uninstall Okta Active Directory Agent and reinstall Okta Active Directory Agent 3.12.0 or greater per the documentation.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:okta:active_directory_agent:3.8.0:*:*:*:*:*:*:*
cpe:2.3:a:okta:active_directory_agent:3.9.0:*:*:*:*:*:*:*
cpe:2.3:a:okta:active_directory_agent:3.10.0:*:*:*:*:*:*:*
cpe:2.3:a:okta:active_directory_agent:3.11.0:*:*:*:*:*:*:*