CVE-2021-22515: Multi-Factor Authentication (MFA) downgrade exposure in NetIQ Advanced Authentication Server
Multi-Factor Authentication (MFA) functionality can be bypassed, allowing the use of single factor authentication in NetIQ Advanced Authentication versions prior to 6.3 SP4 Patch 1.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2021-22515?
CVE-2021-22515 refers to a vulnerability in NetIQ Advanced Authentication versions prior to 6.3 SP4 Patch 1 that allows the bypassing of Multi-Factor Authentication (MFA) functionality, enabling the use of single factor authentication.
Which software versions are affected by CVE-2021-22515?
NetIQ Advanced Authentication versions prior to 6.3 SP4 Patch 1 are affected by CVE-2021-22515.
What is the severity of CVE-2021-22515?
CVE-2021-22515 has a severity rating of 6.5 (medium).
How can the bypass of MFA functionality in NetIQ Advanced Authentication be fixed?
To fix the bypass of MFA functionality, it is recommended to upgrade to NetIQ Advanced Authentication version 6.3 SP4 Patch 1 or a later release.
Where can I find more information about CVE-2021-22515?
More information about CVE-2021-22515 can be found in the NetIQ Advanced Authentication Release Notes.