CVE Published: 20/11/2024 |
CVE Updated: 22/11/2024 |
CVE Year: 2024 Source: Okta |
Vendor: Okta |
Product: Okta Privileged Access Server Agent (SFTD) Status : PUBLISHED
CVE-2024-9875 Description
Okta Privileged Access server agent (SFTD) versions 1.82.0 to 1.84.0 are affected by a privilege escalation vulnerability when the sudo command bundles feature is enabled. To remediate this vulnerability, upgrade the Okta Privileged Access server agent (SFTD) to version 1.87.1 or greater.
Metrics
CVSS Version: 3.1 |
Base Score: 7.1 HIGH Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N