Unquoted Path Vulnerability in Okta Active Directory Agent

Unquoted Path Vulnerability in Okta Active Directory Agent

CVE-2022-1697 · LOW Severity

CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:L

Okta Active Directory Agent versions 3.8.0 through 3.11.0 installed the Okta AD Agent Update Service using an unquoted path. Note: To remediate this vulnerability, you must uninstall Okta Active Directory Agent and reinstall Okta Active Directory Agent 3.12.0 or greater per the documentation.

Learn more about our Web Application Penetration Testing UK.