First published: Tue Sep 06 2022(Updated: )
Okta Active Directory Agent versions 3.8.0 through 3.11.0 installed the Okta AD Agent Update Service using an unquoted path. Note: To remediate this vulnerability, you must uninstall Okta Active Directory Agent and reinstall Okta Active Directory Agent 3.12.0 or greater per the documentation.
Credit: psirt@okta.com
Affected Software | Affected Version | How to fix |
---|---|---|
Okta Active Directory Agent | =3.8.0 | |
Okta Active Directory Agent | =3.9.0 | |
Okta Active Directory Agent | =3.10.0 | |
Okta Active Directory Agent | =3.11.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-1697 is a vulnerability found in Okta Active Directory Agent versions 3.8.0 through 3.11.0 where the Okta AD Agent Update Service is installed using an unquoted path.
CVE-2022-1697 has a severity level of low with a severity value of 3.9.
To fix CVE-2022-1697, you must uninstall Okta Active Directory Agent and reinstall Okta Active Directory Agent 3.12.0 or greater as per the documentation.
You can find more information about CVE-2022-1697 at the following references: [link 1], [link 2], [link 3].
The Common Weakness Enumeration (CWE) associated with CVE-2022-1697 is CWE-428.