First published: Fri Apr 02 2021(Updated: )
Advanced Authentication versions prior to 6.3 SP4 have a potential broken authentication due to improper session management issue.
Credit: security@microfocus.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microfocus Netiq Advanced Authentication | <6.3 | |
Microfocus Netiq Advanced Authentication | =6.3 | |
Microfocus Netiq Advanced Authentication | =6.3-sp1 | |
Microfocus Netiq Advanced Authentication | =6.3-sp2 | |
Microfocus Netiq Advanced Authentication | =6.3-sp3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-22497 is a vulnerability in Advanced Authentication versions prior to 6.3 SP4 that could lead to broken authentication due to improper session management.
Advanced Authentication versions prior to 6.3 SP4, including version 6.3, 6.3-sp1, 6.3-sp2, and 6.3-sp3, are affected by CVE-2021-22497.
CVE-2021-22497 has a severity score of 7.2, which is considered high.
To fix CVE-2021-22497, you should update to Advanced Authentication version 6.3 SP4 or later.
You can find more information about CVE-2021-22497 in the release notes of Advanced Authentication version 6.3 SP4.