First published: Thu Apr 29 2021(Updated: )
Multi-Factor Authentication (MFA) functionality can be bypassed, allowing the use of single factor authentication in NetIQ Advanced Authentication versions prior to 6.3 SP4 Patch 1.
Credit: security@microfocus.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microfocus Netiq Advanced Authentication | <6.3 | |
Microfocus Netiq Advanced Authentication | =6.3 | |
Microfocus Netiq Advanced Authentication | =6.3-sp1 | |
Microfocus Netiq Advanced Authentication | =6.3-sp2 | |
Microfocus Netiq Advanced Authentication | =6.3-sp3 | |
Microfocus Netiq Advanced Authentication | =6.3-sp4 |
Upgrade to NetIQ Advanced Authentication Framework 6.3 SP4 Patch 1
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-22515 refers to a vulnerability in NetIQ Advanced Authentication versions prior to 6.3 SP4 Patch 1 that allows the bypassing of Multi-Factor Authentication (MFA) functionality, enabling the use of single factor authentication.
NetIQ Advanced Authentication versions prior to 6.3 SP4 Patch 1 are affected by CVE-2021-22515.
CVE-2021-22515 has a severity rating of 6.5 (medium).
To fix the bypass of MFA functionality, it is recommended to upgrade to NetIQ Advanced Authentication version 6.3 SP4 Patch 1 or a later release.
More information about CVE-2021-22515 can be found in the NetIQ Advanced Authentication Release Notes.