CVE-2021-22509

HIGH

NetIQ Advance Auth <6.3.5.1 - Info Disclosure

Title source: llm
STIX 2.1

Description

A vulnerability identified in storing and reusing information in Advance Authentication. This issue can lead to leakage of sensitive data to unauthorized user. The issue affects NetIQ Advance Authentication before 6.3.5.1

Scores

CVSS v3 8.1
EPSS 0.0010
EPSS Percentile 26.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-312
Status published
Products (2)
microfocus/netiq_advanced_authentication 6.3 (7 CPE variants)
microfocus/netiq_advanced_authentication < 6.3
Published Aug 28, 2024
Tracked Since Feb 18, 2026