Exposição de Okta

Authentication
50
score de exposição
6.554
sites usam
0
em exploração
0
críticos
Análise Vexday

O histórico de vulnerabilidades catalogadas para o Okta é relativamente enxuto, com 15 CVEs registradas, nenhuma classificada como crítica e nenhuma com exploração ativa confirmada pelo CISA KEV — taxa que se situa abaixo da média geral do catálogo. O tipo de falha mais recorrente é CWE-22 (Path Traversal), o que indica atenção necessária a controles de validação de caminhos de arquivo nas implementações. A CVE mais relevante no momento, CVE-2022-24295, apresenta score EPSS de 0,18, sugerindo probabilidade moderada de exploração, ainda que sem registro confirmado de uso ativo. A ausência de vulnerabilidades novas nos últimos 90 dias pode indicar estabilidade recente no ciclo de divulgação, mas não elimina a necessidade de monitoramento contínuo dado o papel crítico que soluções de identidade como o Okta exercem em cadeias de acesso corporativo.

CVEs

33 resultados
CVE-2022-24295Okta Advanced Server Access Client for Windows prior to version 1.57.0 was found to be vulnerable to command injection via a specially craftEPSS 16.6%CVE-2022-1030Okta Advanced Server Access Client for Linux and macOS prior to version 1.58.0 was found to be vulnerable to command injection via a specialEPSS 1.5%CVE-2023-0093HIGHOkta Advanced Server Access Client versions 1.13.1 through 1.65.0 are vulnerable to command injection due to the third party library webbrowEPSS 1.1%CVE-2024-10327HIGHA vulnerability in Okta Verify for iOS versions 9.25.1 (beta) and 9.27.0 (including beta) allows push notification responses through the iOSEPSS 0.6%CVE-2024-0980HIGHThe Auto-update service for Okta Verify for Windows is vulnerable to two flaws which in combination could be used to execute arbitrary code.EPSS 0.5%CVE-2022-3145MEDIUMAn open redirect vulnerability exists in Okta OIDC Middleware prior to version 5.0.0 allowing an attacker to redirect a user to an arbitraryEPSS 0.4%CVE-2024-0981HIGHOkta Browser Plugin versions 6.5.0 through 6.31.0 (Chrome/Edge/Firefox/Safari) are vulnerable to cross-site scripting. This issue occurs wheEPSS 0.4%CVE-2026-78545MEDIUMImproper Input Sanitization in Okta Access Gateway Application Label ConfigurationEPSS 0.4%CVE-2026-78550MEDIUMImproper Input Handling in Okta Access Gateway Management Console Exception HandlerEPSS 0.4%CVE-2026-78624MEDIUMImproper Path Validation in Okta Access Gateway Backup and Restore FunctionalityEPSS 0.4%CVE-2026-78552MEDIUMValidation Bypass in Okta Access Gateway Custom DirectivesEPSS 0.3%CVE-2025-7371MEDIUMOkta On-Premises Provisioning (OPP) agents log certain user data during administrator-initiated password resets. This vulnerability allows aEPSS 0.3%CVE-2025-66033MEDIUMImproper Memory Cleanup in the Okta Java SDKEPSS 0.3%CVE-2022-1697Okta Active Directory Agent versions 3.8.0 through 3.11.0 installed the Okta AD Agent Update Service using an unquoted path. Note: To remediEPSS 0.3%CVE-2026-78620MEDIUMImproper Path Validation in Okta Access Gateway Kerberos Configuration HandlingEPSS 0.3%CVE-2026-78579MEDIUMImproper Input Sanitization in Okta Access Gateway LDAP Datastore Filter InterpolationEPSS 0.2%CVE-2024-9191HIGHThe Okta Device Access features, provided by the Okta Verify agent for Windows, provides access to the OktaDeviceAccessPipe, which enables aEPSS 0.2%CVE-2024-9875HIGHOkta Privileged Access server agent (SFTD) versions 1.82.0 to 1.84.0 are affected by a privilege escalation vulnerability when the sudo commEPSS 0.2%CVE-2026-78623HIGHImproper Handling of SAML Assertion Attributes in Okta Access Gateway Advanced Mode DatastoresEPSS 0.2%CVE-2024-7061MEDIUMOkta Verify for Windows is vulnerable to privilege escalation through DLL hijacking. The vulnerability is fixed in Okta Verify for Windows vEPSS 0.2%