CVE-2021-22509 Vulnerability Details

  /     /     /  

CVE-2021-22509 Metadata Quick Info

CVE Published: 28/08/2024 | CVE Updated: 28/08/2024 | CVE Year: 2021
Source: OpenText | Vendor: OpenText | Product: NetIQ Advance Authentication
Status : PUBLISHED

CVE-2021-22509 Description

A vulnerability identified in storing and reusing information in Advance Authentication. This issue can lead to leakage of sensitive data to unauthorized user. The issue affects NetIQ Advance Authentication before 6.3.5.1

Metrics

CVSS Version: 3.1 | Base Score: 8.1 HIGH
Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:L

l➤ Exploitability Metrics:
    Attack Vector (AV)* LOCAL
    Attack Complexity (AC)* LOW
    Privileges Required (PR)* LOW
    User Interaction (UI)* REQUIRED
    Scope (S)* CHANGED

l➤ Impact Metrics:
    Confidentiality Impact (C)* HIGH
    Integrity Impact (I)* HIGH
    Availability Impact (A)* LOW

Weakness Enumeration (CWE)

CWE-ID: CWE-312
CWE Name: CWE-312 Cleartext Storage of Sensitive Information
Source: OpenText

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID: CAPEC-191
CAPEC Description: CAPEC-191 Read Sensitive Constants Within an Executable


Source: NVD (National Vulnerability Database).