CVE-2021-22497: Advanced Authentication Improper Session Management
Published Apr 12, 2021
·Updated
Advanced Authentication versions prior to 6.3 SP4 have a potential broken authentication due to improper session management issue.
Affected Software
5 affected components
MicroFocus Netiq Advanced Authentication<6.3
MicroFocus Netiq Advanced Authentication=6.3
MicroFocus Netiq Advanced Authentication=6.3-sp1
MicroFocus Netiq Advanced Authentication=6.3-sp2
MicroFocus Netiq Advanced Authentication=6.3-sp3
Event History
Apr 12, 2021
CVE Published
via MITRE·08:53 PM
Data Sourced
via MITRE·08:53 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2021-22497?
CVE-2021-22497 is a vulnerability in Advanced Authentication versions prior to 6.3 SP4 that could lead to broken authentication due to improper session management.
2
What software is affected by CVE-2021-22497?
Advanced Authentication versions prior to 6.3 SP4, including version 6.3, 6.3-sp1, 6.3-sp2, and 6.3-sp3, are affected by CVE-2021-22497.
3
How severe is CVE-2021-22497?
CVE-2021-22497 has a severity score of 7.2, which is considered high.
4
How can I fix CVE-2021-22497?
To fix CVE-2021-22497, you should update to Advanced Authentication version 6.3 SP4 or later.
5
Where can I find more information about CVE-2021-22497?
You can find more information about CVE-2021-22497 in the release notes of Advanced Authentication version 6.3 SP4.