CVE-2022-1697

LOW

Okta Active Directory Agent <3.12.0 - Path Traversal

Title source: llm
STIX 2.1

Description

Okta Active Directory Agent versions 3.8.0 through 3.11.0 installed the Okta AD Agent Update Service using an unquoted path. Note: To remediate this vulnerability, you must uninstall Okta Active Directory Agent and reinstall Okta Active Directory Agent 3.12.0 or greater per the documentation.

Scores

CVSS v3 3.9
EPSS 0.0007
EPSS Percentile 20.7%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:L

Details

CWE
CWE-428
Status published
Products (4)
okta/active_directory_agent 3.8.0
okta/active_directory_agent 3.9.0
okta/active_directory_agent 3.10.0
okta/active_directory_agent 3.11.0
Published Sep 06, 2022
Tracked Since Feb 18, 2026