Remote Code Execution using Bash command Injection in backup scheduling functionality in NetIQ Advance Authentication
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 5.1epss 0.5%
exploitation probability
0.5%top 58% of all CVEs
observed exploitation
nono source reports it
A vulnerability identified in Advance Authentication that allows bash command Injection in administrative controlled functionality of backup due to improper
handling in provided command parameters. This issue affects NetIQ Advance Authentication version before 6.3.5.1.
CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:L/I:H/A:L
Affected products
OpenText · NetIQ Advance Authentication