CVE-2021-22509: Handling of sensitive data in process memory in NetIQ Advance Authentication
Published Aug 28, 2024
·Updated
A vulnerability identified in storing and reusing information in Advance Authentication. This issue can lead to leakage of sensitive data to unauthorized user. The issue affects NetIQ Advance Authentication before 6.3.5.1
Affected Software
8 affected components
MicroFocus Netiq Advanced Authentication<6.3
MicroFocus Netiq Advanced Authentication=6.3
MicroFocus Netiq Advanced Authentication=6.3-sp1
MicroFocus Netiq Advanced Authentication=6.3-sp2
MicroFocus Netiq Advanced Authentication=6.3-sp3
MicroFocus Netiq Advanced Authentication=6.3-sp4
MicroFocus Netiq Advanced Authentication=6.3-sp4_patch1
MicroFocus Netiq Advanced Authentication=6.3-sp5
Event History
Aug 28, 2024
CVE Published
via MITRE·06:29 AM
Data Sourced
via MITRE·06:29 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-22509?
CVE-2021-22509 is considered a moderate severity vulnerability due to the potential leakage of sensitive data.
2
How do I fix CVE-2021-22509?
To fix CVE-2021-22509, upgrade your NetIQ Advanced Authentication to version 6.3.5.1 or later.
3
What types of data are at risk with CVE-2021-22509?
CVE-2021-22509 can lead to the exposure of sensitive user information to unauthorized users.
4
Which versions of NetIQ Advanced Authentication are affected by CVE-2021-22509?
CVE-2021-22509 affects all versions of NetIQ Advanced Authentication prior to 6.3.5.1.
5
Is CVE-2021-22509 applicable to NetIQ Advanced Authentication 6.3 with service packs?
Yes, CVE-2021-22509 is applicable to NetIQ Advanced Authentication 6.3 including all service packs up to 6.3.4.