A vulnerability identified in Advance Authentication that allows bash command Injection in administrative controlled functionality of backup due to improper
handling in provided command parameters. This issue affects NetIQ Advance Authentication version before 6.3.5.1.
References
Configurations
Configuration 1 (hide)
|
History
13 Sep 2024, 18:04
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:microfocus:netiq_advanced_authentication:6.3:-:*:*:*:*:*:* cpe:2.3:a:microfocus:netiq_advanced_authentication:6.3:sp5:*:*:*:*:*:* cpe:2.3:a:microfocus:netiq_advanced_authentication:*:*:*:*:*:*:*:* cpe:2.3:a:microfocus:netiq_advanced_authentication:6.3:sp4:*:*:*:*:*:* cpe:2.3:a:microfocus:netiq_advanced_authentication:6.3:sp1:*:*:*:*:*:* cpe:2.3:a:microfocus:netiq_advanced_authentication:6.3:sp3:*:*:*:*:*:* cpe:2.3:a:microfocus:netiq_advanced_authentication:6.3:sp4_patch1:*:*:*:*:*:* cpe:2.3:a:microfocus:netiq_advanced_authentication:6.3:sp2:*:*:*:*:*:* |
|
First Time |
Microfocus netiq Advanced Authentication
|
12 Sep 2024, 17:41
Type | Values Removed | Values Added |
---|---|---|
First Time |
Microfocus
Microfocus netiq Advance Authentication |
|
References | () https://www.netiq.com/documentation/advanced-authentication-63/advanced-authentication-releasenotes-6351/data/advanced-authentication-releasenotes-6351.html - Release Notes | |
CPE | cpe:2.3:a:microfocus:netiq_advance_authentication:*:*:*:*:*:*:*:* | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.2 |
28 Aug 2024, 12:57
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
28 Aug 2024, 07:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-08-28 07:15
Updated : 2024-09-13 18:04
NVD link : CVE-2021-38120
Mitre link : CVE-2021-38120
CVE.ORG link : CVE-2021-38120
JSON object : View
Products Affected
microfocus
- netiq_advanced_authentication
CWE
CWE-77
Improper Neutralization of Special Elements used in a Command ('Command Injection')