CVE-2021-38120: Remote Code Execution using Bash command Injection in backup scheduling functionality in NetIQ Advance Authentication
A vulnerability identified in Advance Authentication that allows bash command Injection in administrative controlled functionality of backup due to improper handling in provided command parameters. This issue affects NetIQ Advance Authentication version before 6.3.5.1.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-38120?
CVE-2021-38120 is considered a significant security risk due to the potential for bash command injection.
How do I fix CVE-2021-38120?
To remediate CVE-2021-38120, upgrade to NetIQ Advance Authentication version 6.3.5.1 or later.
What versions of NetIQ Advance Authentication are affected by CVE-2021-38120?
CVE-2021-38120 affects all versions of NetIQ Advance Authentication prior to 6.3.5.1.
What type of vulnerability is CVE-2021-38120?
CVE-2021-38120 is a software vulnerability that allows for bash command injection due to improper handling of command parameters.
Is there a workaround for CVE-2021-38120?
There are no publicly documented workarounds for CVE-2021-38120; upgrading is the recommended action.