Vulnerabilities (CVE)

Filtered by vendor Okta Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-0392 1 Okta 1 Ldap Agent 2023-11-16 N/A 6.7 MEDIUM
The LDAP Agent Update service with versions prior to 5.18 used an unquoted path, which could allow arbitrary code execution.
CVE-2022-1030 3 Apple, Linux, Okta 3 Macos, Linux Kernel, Advanced Server Access 2023-08-08 9.3 HIGH 8.8 HIGH
Okta Advanced Server Access Client for Linux and macOS prior to version 1.58.0 was found to be vulnerable to command injection via a specially crafted URL. An attacker, who has knowledge of a valid team name for the victim and also knows a valid target host where the user has access, can execute commands on the local system.
CVE-2022-24295 1 Okta 1 Advanced Server Access Client For Windows 2023-08-08 6.8 MEDIUM 8.8 HIGH
Okta Advanced Server Access Client for Windows prior to version 1.57.0 was found to be vulnerable to command injection via a specially crafted URL.
CVE-2021-45094 1 Okta 1 Imprivata Privileged Access Management 2023-08-07 N/A 5.4 MEDIUM
Imprivata Privileged Access Management (formally Xton Privileged Access Management) 2.3.202112051108 allows XSS.
CVE-2021-28113 1 Okta 1 Access Gateway 2022-05-27 8.7 HIGH 6.7 MEDIUM
A command injection vulnerability in the cookieDomain and relayDomain parameters of Okta Access Gateway before 2020.9.3 allows attackers (with admin access to the Okta Access Gateway UI) to execute OS commands as a privileged system account.