Записи Okta
30 опубликованных записей вендора okta.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 3
- С записью об исправлении
- 76,7 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')3
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')3
- CWE-94 Improper Control of Generation of Code ('Code Injection')3
- CWE-287 Improper Authentication2
- CWE-428 Unquoted Search Path or Element2
- CWE-532 Insertion of Sensitive Information into Log File2
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEОхват bug bounty
Вендор продукта присутствует в публичной программе. Сопоставление по имени; проверьте текст scope в программе.
Все записи
30 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2022-24295Эксплойта нет | Okta Advanced Server Access Client for Windows prior to version 1.57.0 was found to be vulnerable to command injection via a specially craftokta · advanced server access client for windows · CWE-94 | Высокая8,8 | — | 16,6 % | 21 февр. 2022 г. |
39Наблюдать | CVE-2026-78623Эксплойта нет | Improper Handling of SAML Assertion Attributes in Okta Access Gateway Advanced Mode Datastoresokta · access gateway · CWE-89 | Критическая9,9 | — | 0,5 % | 8 сент. 2026 г. |
35Наблюдать | CVE-2022-1030Эксплойта нет | Okta Advanced Server Access Client for Linux and macOS prior to version 1.58.0 was found to be vulnerable to command injection via a specialokta · advanced server access · CWE-78 | Высокая8,8 | — | 1,5 % | 23 мар. 2022 г. |
35Наблюдать | CVE-2023-0093Эксплойта нет | Okta Advanced Server Access Client versions 1.13.1 through 1.65.0 are vulnerable to command injection due to the third party library webbrowokta · advanced server access · CWE-77 | Высокая8,8 | — | 1,1 % | 6 мар. 2023 г. |
33Наблюдать | CVE-2021-28113Эксплойта нет | A command injection vulnerability in the cookieDomain and relayDomain parameters of Okta Access Gateway before 2020.9.3 allows attackers (wiokta · access gateway · CWE-78 | Средняя6,7 | — | 22,3 % | 2 апр. 2021 г. |
33Наблюдать | CVE-2025-67505Эксплойта нет | Race condition in the Okta Java SDKokta · java management sdk · CWE-362 | Высокая8,4 | — | 0,2 % | 10 дек. 2025 г. |
32Наблюдать | CVE-2024-10327Эксплойта нет | A vulnerability in Okta Verify for iOS versions 9.25.1 (beta) and 9.27.0 (including beta) allows push notification responses through the iOSokta · okta verify for ios · CWE-287 | Высокая8,1 | — | 0,6 % | 24 окт. 2024 г. |
31Наблюдать | CVE-2024-9191Эксплойта нет | The Okta Device Access features, provided by the Okta Verify agent for Windows, provides access to the OktaDeviceAccessPipe, which enables aokta · verify · CWE-276 | Высокая7,8 | — | 0,2 % | 1 нояб. 2024 г. |
31Наблюдать | CVE-2024-7061Эксплойта нет | Okta Verify for Windows is vulnerable to privilege escalation through DLL hijacking.okta · verify · CWE-22 | Высокая7,8 | — | 0,2 % | 7 авг. 2024 г. |
28Наблюдать | CVE-2024-0980Эксплойта нет | The Auto-update service for Okta Verify for Windows is vulnerable to two flaws which in combination could be used to execute arbitrary code.okta · okta verify for windows · CWE-22 | Высокая7,1 | — | 0,5 % | 27 мар. 2024 г. |
28Наблюдать | CVE-2026-78545Эксплойта нет | Improper Input Sanitization in Okta Access Gateway Application Label Configurationokta · access gateway · CWE-94 | Высокая7,2 | — | 0,4 % | 8 сент. 2026 г. |
28Наблюдать | CVE-2026-78550Эксплойта нет | Improper Input Handling in Okta Access Gateway Management Console Exception Handlerokta · access gateway · CWE-95 | Высокая7,2 | — | 0,4 % | 8 сент. 2026 г. |
28Наблюдать | CVE-2024-9875Эксплойта нет | Okta Privileged Access server agent (SFTD) versions 1.82.0 to 1.84.0 are affected by a privilege escalation vulnerability when the sudo commokta · okta privileged access server agent (sftd) · CWE-20 | Высокая7,1 | — | 0,2 % | 21 нояб. 2024 г. |
26Наблюдать | CVE-2026-78626Эксплойта нет | Improper Input Sanitization in Okta Access Gateway Protected Rulesokta · access gateway · CWE-863 | Средняя6,5 | — | 0,4 % | 8 сент. 2026 г. |
26Наблюдать | CVE-2026-78579Эксплойта нет | Improper Input Sanitization in Okta Access Gateway LDAP Datastore Filter Interpolationokta · access gateway · CWE-90 | Средняя6,5 | — | 0,2 % | 8 сент. 2026 г. |
26Наблюдать | CVE-2026-78625Эксплойта нет | Insufficient Validation of Dashboard Application Labels in Okta Access Gateway Dashboard Site Configurationokta · access gateway · CWE-94 | Средняя6,7 | — | 0,2 % | 8 сент. 2026 г. |
26Наблюдать | CVE-2026-78630Эксплойта нет | Improper Input Neutralization in Okta Access Gateway SNMP Configuration Processingokta · access gateway · CWE-78 | Средняя6,7 | — | 0,2 % | 8 сент. 2026 г. |
26Наблюдать | CVE-2023-0392Эксплойта нет | The LDAP Agent Update service with versions prior to 5.18 used an unquoted path, which could allow arbitrary code execution.okta · ldap agent · CWE-428 | Средняя6,7 | — | 0,2 % | 8 нояб. 2023 г. |
26Наблюдать | CVE-2026-78560Эксплойта нет | Improper Authentication Validation in Okta Access Gateway Pass-Through Authentication Sourceokta · access gateway · CWE-287 | Средняя6,5 | — | 0,2 % | 8 сент. 2026 г. |
25Наблюдать | CVE-2026-78574Эксплойта нет | Improper Assembly Resolution in Okta Hyperdrive Integration Plugin Registry Handlingokta · hyperdrive · CWE-426 | Средняя6,3 | — | 0,1 % | 8 сент. 2026 г. |
22Наблюдать | CVE-2026-78629Эксплойта нет | Improper Authentication Verification in the Okta Hyperdrive Agent MFA Response Handlingokta · hyperdrive · CWE-303 | Средняя5,5 | — | 0,1 % | 8 сент. 2026 г. |
22Наблюдать | CVE-2026-78627Эксплойта нет | Improper Credential Protection in Okta Hyperdrive Integration Installer Loggingokta · hyperdrive · CWE-532 | Средняя5,5 | — | 0,1 % | 8 сент. 2026 г. |
22Наблюдать | CVE-2026-78631Эксплойта нет | Improper Restriction of Sensitive Information in Okta Hyperdrive Agent Loggingokta · hyperdrive · CWE-532 | Средняя5,5 | — | 0,1 % | 8 сент. 2026 г. |
21Наблюдать | CVE-2021-45094Эксплойта нет | Imprivata Privileged Access Management (formally Xton Privileged Access Management) 2.3.202112051108 allows XSS.okta · imprivata privileged access management · CWE-79 | Средняя5,4 | — | 0,6 % | 20 июл. 2023 г. |
21Наблюдать | CVE-2025-66033Эксплойта нет | Improper Memory Cleanup in the Okta Java SDKokta · java management sdk · CWE-401 | Средняя5,3 | — | 0,3 % | 10 дек. 2025 г. |
- CVE-2022-2429540В плане
Okta Advanced Server Access Client for Windows prior to version 1.57.0 was found to be vulnerable to command injection via a specially craft
ВысокаяCVSS 8,8Эксплойта нетEPSS 17 %okta · advanced server access client for windows21 февр. 2022 г.
- CVE-2026-7862339Наблюдать
Improper Handling of SAML Assertion Attributes in Okta Access Gateway Advanced Mode Datastores
КритическаяCVSS 9,9Эксплойта нетEPSS 0 %okta · access gateway8 сент. 2026 г.
- CVE-2022-103035Наблюдать
Okta Advanced Server Access Client for Linux and macOS prior to version 1.58.0 was found to be vulnerable to command injection via a special
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %okta · advanced server access23 мар. 2022 г.
- CVE-2023-009335Наблюдать
Okta Advanced Server Access Client versions 1.13.1 through 1.65.0 are vulnerable to command injection due to the third party library webbrow
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %okta · advanced server access6 мар. 2023 г.
- CVE-2021-2811333Наблюдать
A command injection vulnerability in the cookieDomain and relayDomain parameters of Okta Access Gateway before 2020.9.3 allows attackers (wi
СредняяCVSS 6,7Эксплойта нетEPSS 22 %okta · access gateway2 апр. 2021 г.
- CVE-2025-6750533Наблюдать
Race condition in the Okta Java SDK
ВысокаяCVSS 8,4Эксплойта нетEPSS 0 %okta · java management sdk10 дек. 2025 г.
- CVE-2024-1032732Наблюдать
A vulnerability in Okta Verify for iOS versions 9.25.1 (beta) and 9.27.0 (including beta) allows push notification responses through the iOS
ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %okta · okta verify for ios24 окт. 2024 г.
- CVE-2024-919131Наблюдать
The Okta Device Access features, provided by the Okta Verify agent for Windows, provides access to the OktaDeviceAccessPipe, which enables a
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %okta · verify1 нояб. 2024 г.
- CVE-2024-706131Наблюдать
Okta Verify for Windows is vulnerable to privilege escalation through DLL hijacking.
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %okta · verify7 авг. 2024 г.
- CVE-2024-098028Наблюдать
The Auto-update service for Okta Verify for Windows is vulnerable to two flaws which in combination could be used to execute arbitrary code.
ВысокаяCVSS 7,1Эксплойта нетEPSS 0 %okta · okta verify for windows27 мар. 2024 г.
- CVE-2026-7854528Наблюдать
Improper Input Sanitization in Okta Access Gateway Application Label Configuration
ВысокаяCVSS 7,2Эксплойта нетEPSS 0 %okta · access gateway8 сент. 2026 г.
- CVE-2026-7855028Наблюдать
Improper Input Handling in Okta Access Gateway Management Console Exception Handler
ВысокаяCVSS 7,2Эксплойта нетEPSS 0 %okta · access gateway8 сент. 2026 г.
- CVE-2024-987528Наблюдать
Okta Privileged Access server agent (SFTD) versions 1.82.0 to 1.84.0 are affected by a privilege escalation vulnerability when the sudo comm
ВысокаяCVSS 7,1Эксплойта нетEPSS 0 %okta · okta privileged access server agent (sftd)21 нояб. 2024 г.
- CVE-2026-7862626Наблюдать
Improper Input Sanitization in Okta Access Gateway Protected Rules
СредняяCVSS 6,5Эксплойта нетEPSS 0 %okta · access gateway8 сент. 2026 г.
- CVE-2026-7857926Наблюдать
Improper Input Sanitization in Okta Access Gateway LDAP Datastore Filter Interpolation
СредняяCVSS 6,5Эксплойта нетEPSS 0 %okta · access gateway8 сент. 2026 г.
- CVE-2026-7862526Наблюдать
Insufficient Validation of Dashboard Application Labels in Okta Access Gateway Dashboard Site Configuration
СредняяCVSS 6,7Эксплойта нетEPSS 0 %okta · access gateway8 сент. 2026 г.
- CVE-2026-7863026Наблюдать
Improper Input Neutralization in Okta Access Gateway SNMP Configuration Processing
СредняяCVSS 6,7Эксплойта нетEPSS 0 %okta · access gateway8 сент. 2026 г.
- CVE-2023-039226Наблюдать
The LDAP Agent Update service with versions prior to 5.18 used an unquoted path, which could allow arbitrary code execution.
СредняяCVSS 6,7Эксплойта нетEPSS 0 %okta · ldap agent8 нояб. 2023 г.
- CVE-2026-7856026Наблюдать
Improper Authentication Validation in Okta Access Gateway Pass-Through Authentication Source
СредняяCVSS 6,5Эксплойта нетEPSS 0 %okta · access gateway8 сент. 2026 г.
- CVE-2026-7857425Наблюдать
Improper Assembly Resolution in Okta Hyperdrive Integration Plugin Registry Handling
СредняяCVSS 6,3Эксплойта нетEPSS 0 %okta · hyperdrive8 сент. 2026 г.
- CVE-2026-7862922Наблюдать
Improper Authentication Verification in the Okta Hyperdrive Agent MFA Response Handling
СредняяCVSS 5,5Эксплойта нетEPSS 0 %okta · hyperdrive8 сент. 2026 г.
- CVE-2026-7862722Наблюдать
Improper Credential Protection in Okta Hyperdrive Integration Installer Logging
СредняяCVSS 5,5Эксплойта нетEPSS 0 %okta · hyperdrive8 сент. 2026 г.
- CVE-2026-7863122Наблюдать
Improper Restriction of Sensitive Information in Okta Hyperdrive Agent Logging
СредняяCVSS 5,5Эксплойта нетEPSS 0 %okta · hyperdrive8 сент. 2026 г.
- CVE-2021-4509421Наблюдать
Imprivata Privileged Access Management (formally Xton Privileged Access Management) 2.3.202112051108 allows XSS.
СредняяCVSS 5,4Эксплойта нетEPSS 1 %okta · imprivata privileged access management20 июл. 2023 г.
- CVE-2025-6603321Наблюдать
Improper Memory Cleanup in the Okta Java SDK
СредняяCVSS 5,3Эксплойта нетEPSS 0 %okta · java management sdk10 дек. 2025 г.