İçeriğe atla
Noroxi

Okta kayıtları

okta üreticisine ait 30 yayımlanmış kayıt.

Bug bounty kapsamı

Ürünün üreticisi herkese açık bir programda görünüyor. Eşleşme ad üzerinden yapıldı; kapsam metnini programda doğrulayın.

Tüm kayıtlar

30 kayıt
  • CVE-2022-24295
    40Planlayın

    Okta Advanced Server Access Client for Windows prior to version 1.57.0 was found to be vulnerable to command injection via a specially craft

    YüksekCVSS 8,8İstismar yokEPSS %17

    okta · advanced server access client for windows21 Şub 2022

  • CVE-2026-78623
    39İzleyin

    Improper Handling of SAML Assertion Attributes in Okta Access Gateway Advanced Mode Datastores

    KritikCVSS 9,9İstismar yokEPSS %0

    okta · access gateway8 Eyl 2026

  • CVE-2022-1030
    35İzleyin

    Okta Advanced Server Access Client for Linux and macOS prior to version 1.58.0 was found to be vulnerable to command injection via a special

    YüksekCVSS 8,8İstismar yokEPSS %1

    okta · advanced server access23 Mar 2022

  • CVE-2023-0093
    35İzleyin

    Okta Advanced Server Access Client versions 1.13.1 through 1.65.0 are vulnerable to command injection due to the third party library webbrow

    YüksekCVSS 8,8İstismar yokEPSS %1

    okta · advanced server access6 Mar 2023

  • CVE-2021-28113
    33İzleyin

    A command injection vulnerability in the cookieDomain and relayDomain parameters of Okta Access Gateway before 2020.9.3 allows attackers (wi

    OrtaCVSS 6,7İstismar yokEPSS %22

    okta · access gateway2 Nis 2021

  • CVE-2025-67505
    33İzleyin

    Race condition in the Okta Java SDK

    YüksekCVSS 8,4İstismar yokEPSS %0

    okta · java management sdk10 Ara 2025

  • CVE-2024-10327
    32İzleyin

    A vulnerability in Okta Verify for iOS versions 9.25.1 (beta) and 9.27.0 (including beta) allows push notification responses through the iOS

    YüksekCVSS 8,1İstismar yokEPSS %1

    okta · okta verify for ios24 Eki 2024

  • CVE-2024-9191
    31İzleyin

    The Okta Device Access features, provided by the Okta Verify agent for Windows, provides access to the OktaDeviceAccessPipe, which enables a

    YüksekCVSS 7,8İstismar yokEPSS %0

    okta · verify1 Kas 2024

  • CVE-2024-7061
    31İzleyin

    Okta Verify for Windows is vulnerable to privilege escalation through DLL hijacking.

    YüksekCVSS 7,8İstismar yokEPSS %0

    okta · verify7 Ağu 2024

  • CVE-2026-78545
    28İzleyin

    Improper Input Sanitization in Okta Access Gateway Application Label Configuration

    YüksekCVSS 7,2İstismar yokEPSS %0

    okta · access gateway8 Eyl 2026

  • CVE-2026-78550
    28İzleyin

    Improper Input Handling in Okta Access Gateway Management Console Exception Handler

    YüksekCVSS 7,2İstismar yokEPSS %0

    okta · access gateway8 Eyl 2026

  • CVE-2024-0980
    28İzleyin

    The Auto-update service for Okta Verify for Windows is vulnerable to two flaws which in combination could be used to execute arbitrary code.

    YüksekCVSS 7,1İstismar yokEPSS %0

    okta · okta verify for windows27 Mar 2024

  • CVE-2024-9875
    28İzleyin

    Okta Privileged Access server agent (SFTD) versions 1.82.0 to 1.84.0 are affected by a privilege escalation vulnerability when the sudo comm

    YüksekCVSS 7,1İstismar yokEPSS %0

    okta · okta privileged access server agent (sftd)21 Kas 2024

  • CVE-2026-78626
    26İzleyin

    Improper Input Sanitization in Okta Access Gateway Protected Rules

    OrtaCVSS 6,5İstismar yokEPSS %0

    okta · access gateway8 Eyl 2026

  • CVE-2026-78579
    26İzleyin

    Improper Input Sanitization in Okta Access Gateway LDAP Datastore Filter Interpolation

    OrtaCVSS 6,5İstismar yokEPSS %0

    okta · access gateway8 Eyl 2026

  • CVE-2026-78625
    26İzleyin

    Insufficient Validation of Dashboard Application Labels in Okta Access Gateway Dashboard Site Configuration

    OrtaCVSS 6,7İstismar yokEPSS %0

    okta · access gateway8 Eyl 2026

  • CVE-2026-78630
    26İzleyin

    Improper Input Neutralization in Okta Access Gateway SNMP Configuration Processing

    OrtaCVSS 6,7İstismar yokEPSS %0

    okta · access gateway8 Eyl 2026

  • CVE-2023-0392
    26İzleyin

    The LDAP Agent Update service with versions prior to 5.18 used an unquoted path, which could allow arbitrary code execution.

    OrtaCVSS 6,7İstismar yokEPSS %0

    okta · ldap agent8 Kas 2023

  • CVE-2026-78560
    26İzleyin

    Improper Authentication Validation in Okta Access Gateway Pass-Through Authentication Source

    OrtaCVSS 6,5İstismar yokEPSS %0

    okta · access gateway8 Eyl 2026

  • CVE-2026-78574
    25İzleyin

    Improper Assembly Resolution in Okta Hyperdrive Integration Plugin Registry Handling

    OrtaCVSS 6,3İstismar yokEPSS %0

    okta · hyperdrive8 Eyl 2026

  • CVE-2026-78629
    22İzleyin

    Improper Authentication Verification in the Okta Hyperdrive Agent MFA Response Handling

    OrtaCVSS 5,5İstismar yokEPSS %0

    okta · hyperdrive8 Eyl 2026

  • CVE-2026-78627
    22İzleyin

    Improper Credential Protection in Okta Hyperdrive Integration Installer Logging

    OrtaCVSS 5,5İstismar yokEPSS %0

    okta · hyperdrive8 Eyl 2026

  • CVE-2026-78631
    22İzleyin

    Improper Restriction of Sensitive Information in Okta Hyperdrive Agent Logging

    OrtaCVSS 5,5İstismar yokEPSS %0

    okta · hyperdrive8 Eyl 2026

  • CVE-2021-45094
    21İzleyin

    Imprivata Privileged Access Management (formally Xton Privileged Access Management) 2.3.202112051108 allows XSS.

    OrtaCVSS 5,4İstismar yokEPSS %1

    okta · imprivata privileged access management20 Tem 2023

  • CVE-2025-66033
    21İzleyin

    Improper Memory Cleanup in the Okta Java SDK

    OrtaCVSS 5,3İstismar yokEPSS %0

    okta · java management sdk10 Ara 2025