Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2021-38120


A vulnerability identified in Advance Authentication that allows bash command Injection in administrative controlled functionality of backup due to improper handling in provided command parameters. This issue affects NetIQ Advance Authentication version before 6.3.5.1.


Published

2024-08-28T07:15:07.303

Last Modified

2024-09-13T18:04:28.527

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 5.1 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-77
  • Type: Primary
    CWE-77

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application microfocus netiq_advanced_authentication < 6.3 Yes
Application microfocus netiq_advanced_authentication 6.3 Yes
Application microfocus netiq_advanced_authentication 6.3 Yes
Application microfocus netiq_advanced_authentication 6.3 Yes
Application microfocus netiq_advanced_authentication 6.3 Yes
Application microfocus netiq_advanced_authentication 6.3 Yes
Application microfocus netiq_advanced_authentication 6.3 Yes
Application microfocus netiq_advanced_authentication 6.3 Yes

References