« Volver al listado

CVE-2022-1697

Estado: ModificadaBaja (3.9)—

Okta Active Directory Agent versions 3.8.0 through 3.11.0 installed the Okta AD Agent Update Service using an unquoted path. Note: To remediate this vulnerability, you must uninstall Okta Active Directory Agent and reinstall Okta Active Directory Agent 3.12.0 or greater per the documentation.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2022-1697",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 3.9,
          "attackVector": "LOCAL",
          "baseSeverity": "LOW",
          "vectorString": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:L",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "LOW",
          "privilegesRequired": "HIGH",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 3.4,
        "exploitabilityScore": 0.5
      }
    ]
  },
  "affected": [
    {
      "source": "psirt@okta.com",
      "affectedData": [
        {
          "vendor": "Okta",
          "product": "Okta Active Directory Agent",
          "versions": [
            {
              "status": "affected",
              "version": "3.8.0, 3.9.0, 3.10.0, 3.11.0"
            }
          ]
        }
      ]
    }
  ],
  "published": "2022-09-06T18:15:10.493",
  "references": [
    {
      "url": "https://help.okta.com/en-us/Content/Topics/Directory/ad-agent-update.htm",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "psirt@okta.com"
    },
    {
      "url": "https://support.okta.com/help/s/article/Security-Notice-CVE-2022-1697-FAQ",
      "tags": [
        "Mitigation",
        "Vendor Advisory"
      ],
      "source": "psirt@okta.com"
    },
    {
      "url": "https://trust.okta.com/security-advisories/okta-active-directory-agent-cve-2022-1697",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "psirt@okta.com"
    },
    {
      "url": "https://help.okta.com/en-us/Content/Topics/Directory/ad-agent-update.htm",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://support.okta.com/help/s/article/Security-Notice-CVE-2022-1697-FAQ",
      "tags": [
        "Mitigation",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://trust.okta.com/security-advisories/okta-active-directory-agent-cve-2022-1697",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-428"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Okta Active Directory Agent versions 3.8.0 through 3.11.0 installed the Okta AD Agent Update Service using an unquoted path. Note: To remediate this vulnerability, you must uninstall Okta Active Directory Agent and reinstall Okta Active Directory Agent 3.12.0 or greater per the documentation."
    },
    {
      "lang": "es",
      "value": "Las versiones 3.8.0 a 3.11.0 del Agente de Okta Active Directory instalan el Servicio de Actualización del Agente de Okta AD utilizando una ruta no citada. Nota: Para corregir esta vulnerabilidad, debe desinstalar el Agente de Okta Active Directory y volver a instalar el Agente de Okta Active Directory 3.12.0 o superior según la documentación"
    }
  ],
  "lastModified": "2026-06-17T04:22:56.347",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:okta:active_directory_agent:3.8.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "442B7B70-70D7-488D-BAC4-7B060CCB1388"
            },
            {
              "criteria": "cpe:2.3:a:okta:active_directory_agent:3.9.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E0B869CF-7CFB-4288-B21B-C959136BE293"
            },
            {
              "criteria": "cpe:2.3:a:okta:active_directory_agent:3.10.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "07931E64-69B0-4081-99A8-9FF8E6989E2C"
            },
            {
              "criteria": "cpe:2.3:a:okta:active_directory_agent:3.11.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C8403CAC-AA6E-4B65-B02D-0DA097D9E53B"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "psirt@okta.com"
}