Okta kayıtları
okta üreticisine ait 30 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 3
- Düzeltme kaydı olan
- %76,7
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')3
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')3
- CWE-94 Improper Control of Generation of Code ('Code Injection')3
- CWE-287 Improper Authentication2
- CWE-428 Unquoted Search Path or Element2
- CWE-532 Insertion of Sensitive Information into Log File2
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWEBug bounty kapsamı
Ürünün üreticisi herkese açık bir programda görünüyor. Eşleşme ad üzerinden yapıldı; kapsam metnini programda doğrulayın.
Tüm kayıtlar
30 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2022-24295İstismar yok | Okta Advanced Server Access Client for Windows prior to version 1.57.0 was found to be vulnerable to command injection via a specially craftokta · advanced server access client for windows · CWE-94 | Yüksek8,8 | — | %16,6 | 21 Şub 2022 |
39İzleyin | CVE-2026-78623İstismar yok | Improper Handling of SAML Assertion Attributes in Okta Access Gateway Advanced Mode Datastoresokta · access gateway · CWE-89 | Kritik9,9 | — | %0,5 | 8 Eyl 2026 |
35İzleyin | CVE-2022-1030İstismar yok | Okta Advanced Server Access Client for Linux and macOS prior to version 1.58.0 was found to be vulnerable to command injection via a specialokta · advanced server access · CWE-78 | Yüksek8,8 | — | %1,5 | 23 Mar 2022 |
35İzleyin | CVE-2023-0093İstismar yok | Okta Advanced Server Access Client versions 1.13.1 through 1.65.0 are vulnerable to command injection due to the third party library webbrowokta · advanced server access · CWE-77 | Yüksek8,8 | — | %1,1 | 6 Mar 2023 |
33İzleyin | CVE-2021-28113İstismar yok | A command injection vulnerability in the cookieDomain and relayDomain parameters of Okta Access Gateway before 2020.9.3 allows attackers (wiokta · access gateway · CWE-78 | Orta6,7 | — | %22,3 | 2 Nis 2021 |
33İzleyin | CVE-2025-67505İstismar yok | Race condition in the Okta Java SDKokta · java management sdk · CWE-362 | Yüksek8,4 | — | %0,2 | 10 Ara 2025 |
32İzleyin | CVE-2024-10327İstismar yok | A vulnerability in Okta Verify for iOS versions 9.25.1 (beta) and 9.27.0 (including beta) allows push notification responses through the iOSokta · okta verify for ios · CWE-287 | Yüksek8,1 | — | %0,6 | 24 Eki 2024 |
31İzleyin | CVE-2024-9191İstismar yok | The Okta Device Access features, provided by the Okta Verify agent for Windows, provides access to the OktaDeviceAccessPipe, which enables aokta · verify · CWE-276 | Yüksek7,8 | — | %0,2 | 1 Kas 2024 |
31İzleyin | CVE-2024-7061İstismar yok | Okta Verify for Windows is vulnerable to privilege escalation through DLL hijacking.okta · verify · CWE-22 | Yüksek7,8 | — | %0,2 | 7 Ağu 2024 |
28İzleyin | CVE-2026-78545İstismar yok | Improper Input Sanitization in Okta Access Gateway Application Label Configurationokta · access gateway · CWE-94 | Yüksek7,2 | — | %0,5 | 8 Eyl 2026 |
28İzleyin | CVE-2026-78550İstismar yok | Improper Input Handling in Okta Access Gateway Management Console Exception Handlerokta · access gateway · CWE-95 | Yüksek7,2 | — | %0,5 | 8 Eyl 2026 |
28İzleyin | CVE-2024-0980İstismar yok | The Auto-update service for Okta Verify for Windows is vulnerable to two flaws which in combination could be used to execute arbitrary code.okta · okta verify for windows · CWE-22 | Yüksek7,1 | — | %0,5 | 27 Mar 2024 |
28İzleyin | CVE-2024-9875İstismar yok | Okta Privileged Access server agent (SFTD) versions 1.82.0 to 1.84.0 are affected by a privilege escalation vulnerability when the sudo commokta · okta privileged access server agent (sftd) · CWE-20 | Yüksek7,1 | — | %0,2 | 21 Kas 2024 |
26İzleyin | CVE-2026-78626İstismar yok | Improper Input Sanitization in Okta Access Gateway Protected Rulesokta · access gateway · CWE-863 | Orta6,5 | — | %0,4 | 8 Eyl 2026 |
26İzleyin | CVE-2026-78579İstismar yok | Improper Input Sanitization in Okta Access Gateway LDAP Datastore Filter Interpolationokta · access gateway · CWE-90 | Orta6,5 | — | %0,2 | 8 Eyl 2026 |
26İzleyin | CVE-2026-78625İstismar yok | Insufficient Validation of Dashboard Application Labels in Okta Access Gateway Dashboard Site Configurationokta · access gateway · CWE-94 | Orta6,7 | — | %0,2 | 8 Eyl 2026 |
26İzleyin | CVE-2026-78630İstismar yok | Improper Input Neutralization in Okta Access Gateway SNMP Configuration Processingokta · access gateway · CWE-78 | Orta6,7 | — | %0,2 | 8 Eyl 2026 |
26İzleyin | CVE-2023-0392İstismar yok | The LDAP Agent Update service with versions prior to 5.18 used an unquoted path, which could allow arbitrary code execution.okta · ldap agent · CWE-428 | Orta6,7 | — | %0,2 | 8 Kas 2023 |
26İzleyin | CVE-2026-78560İstismar yok | Improper Authentication Validation in Okta Access Gateway Pass-Through Authentication Sourceokta · access gateway · CWE-287 | Orta6,5 | — | %0,2 | 8 Eyl 2026 |
25İzleyin | CVE-2026-78574İstismar yok | Improper Assembly Resolution in Okta Hyperdrive Integration Plugin Registry Handlingokta · hyperdrive · CWE-426 | Orta6,3 | — | %0,1 | 8 Eyl 2026 |
22İzleyin | CVE-2026-78629İstismar yok | Improper Authentication Verification in the Okta Hyperdrive Agent MFA Response Handlingokta · hyperdrive · CWE-303 | Orta5,5 | — | %0,1 | 8 Eyl 2026 |
22İzleyin | CVE-2026-78627İstismar yok | Improper Credential Protection in Okta Hyperdrive Integration Installer Loggingokta · hyperdrive · CWE-532 | Orta5,5 | — | %0,1 | 8 Eyl 2026 |
22İzleyin | CVE-2026-78631İstismar yok | Improper Restriction of Sensitive Information in Okta Hyperdrive Agent Loggingokta · hyperdrive · CWE-532 | Orta5,5 | — | %0,1 | 8 Eyl 2026 |
21İzleyin | CVE-2021-45094İstismar yok | Imprivata Privileged Access Management (formally Xton Privileged Access Management) 2.3.202112051108 allows XSS.okta · imprivata privileged access management · CWE-79 | Orta5,4 | — | %0,6 | 20 Tem 2023 |
21İzleyin | CVE-2025-66033İstismar yok | Improper Memory Cleanup in the Okta Java SDKokta · java management sdk · CWE-401 | Orta5,3 | — | %0,3 | 10 Ara 2025 |
- CVE-2022-2429540Planlayın
Okta Advanced Server Access Client for Windows prior to version 1.57.0 was found to be vulnerable to command injection via a specially craft
YüksekCVSS 8,8İstismar yokEPSS %17okta · advanced server access client for windows21 Şub 2022
- CVE-2026-7862339İzleyin
Improper Handling of SAML Assertion Attributes in Okta Access Gateway Advanced Mode Datastores
KritikCVSS 9,9İstismar yokEPSS %0okta · access gateway8 Eyl 2026
- CVE-2022-103035İzleyin
Okta Advanced Server Access Client for Linux and macOS prior to version 1.58.0 was found to be vulnerable to command injection via a special
YüksekCVSS 8,8İstismar yokEPSS %1okta · advanced server access23 Mar 2022
- CVE-2023-009335İzleyin
Okta Advanced Server Access Client versions 1.13.1 through 1.65.0 are vulnerable to command injection due to the third party library webbrow
YüksekCVSS 8,8İstismar yokEPSS %1okta · advanced server access6 Mar 2023
- CVE-2021-2811333İzleyin
A command injection vulnerability in the cookieDomain and relayDomain parameters of Okta Access Gateway before 2020.9.3 allows attackers (wi
OrtaCVSS 6,7İstismar yokEPSS %22okta · access gateway2 Nis 2021
- CVE-2025-6750533İzleyin
Race condition in the Okta Java SDK
YüksekCVSS 8,4İstismar yokEPSS %0okta · java management sdk10 Ara 2025
- CVE-2024-1032732İzleyin
A vulnerability in Okta Verify for iOS versions 9.25.1 (beta) and 9.27.0 (including beta) allows push notification responses through the iOS
YüksekCVSS 8,1İstismar yokEPSS %1okta · okta verify for ios24 Eki 2024
- CVE-2024-919131İzleyin
The Okta Device Access features, provided by the Okta Verify agent for Windows, provides access to the OktaDeviceAccessPipe, which enables a
YüksekCVSS 7,8İstismar yokEPSS %0okta · verify1 Kas 2024
- CVE-2024-706131İzleyin
Okta Verify for Windows is vulnerable to privilege escalation through DLL hijacking.
YüksekCVSS 7,8İstismar yokEPSS %0okta · verify7 Ağu 2024
- CVE-2026-7854528İzleyin
Improper Input Sanitization in Okta Access Gateway Application Label Configuration
YüksekCVSS 7,2İstismar yokEPSS %0okta · access gateway8 Eyl 2026
- CVE-2026-7855028İzleyin
Improper Input Handling in Okta Access Gateway Management Console Exception Handler
YüksekCVSS 7,2İstismar yokEPSS %0okta · access gateway8 Eyl 2026
- CVE-2024-098028İzleyin
The Auto-update service for Okta Verify for Windows is vulnerable to two flaws which in combination could be used to execute arbitrary code.
YüksekCVSS 7,1İstismar yokEPSS %0okta · okta verify for windows27 Mar 2024
- CVE-2024-987528İzleyin
Okta Privileged Access server agent (SFTD) versions 1.82.0 to 1.84.0 are affected by a privilege escalation vulnerability when the sudo comm
YüksekCVSS 7,1İstismar yokEPSS %0okta · okta privileged access server agent (sftd)21 Kas 2024
- CVE-2026-7862626İzleyin
Improper Input Sanitization in Okta Access Gateway Protected Rules
OrtaCVSS 6,5İstismar yokEPSS %0okta · access gateway8 Eyl 2026
- CVE-2026-7857926İzleyin
Improper Input Sanitization in Okta Access Gateway LDAP Datastore Filter Interpolation
OrtaCVSS 6,5İstismar yokEPSS %0okta · access gateway8 Eyl 2026
- CVE-2026-7862526İzleyin
Insufficient Validation of Dashboard Application Labels in Okta Access Gateway Dashboard Site Configuration
OrtaCVSS 6,7İstismar yokEPSS %0okta · access gateway8 Eyl 2026
- CVE-2026-7863026İzleyin
Improper Input Neutralization in Okta Access Gateway SNMP Configuration Processing
OrtaCVSS 6,7İstismar yokEPSS %0okta · access gateway8 Eyl 2026
- CVE-2023-039226İzleyin
The LDAP Agent Update service with versions prior to 5.18 used an unquoted path, which could allow arbitrary code execution.
OrtaCVSS 6,7İstismar yokEPSS %0okta · ldap agent8 Kas 2023
- CVE-2026-7856026İzleyin
Improper Authentication Validation in Okta Access Gateway Pass-Through Authentication Source
OrtaCVSS 6,5İstismar yokEPSS %0okta · access gateway8 Eyl 2026
- CVE-2026-7857425İzleyin
Improper Assembly Resolution in Okta Hyperdrive Integration Plugin Registry Handling
OrtaCVSS 6,3İstismar yokEPSS %0okta · hyperdrive8 Eyl 2026
- CVE-2026-7862922İzleyin
Improper Authentication Verification in the Okta Hyperdrive Agent MFA Response Handling
OrtaCVSS 5,5İstismar yokEPSS %0okta · hyperdrive8 Eyl 2026
- CVE-2026-7862722İzleyin
Improper Credential Protection in Okta Hyperdrive Integration Installer Logging
OrtaCVSS 5,5İstismar yokEPSS %0okta · hyperdrive8 Eyl 2026
- CVE-2026-7863122İzleyin
Improper Restriction of Sensitive Information in Okta Hyperdrive Agent Logging
OrtaCVSS 5,5İstismar yokEPSS %0okta · hyperdrive8 Eyl 2026
- CVE-2021-4509421İzleyin
Imprivata Privileged Access Management (formally Xton Privileged Access Management) 2.3.202112051108 allows XSS.
OrtaCVSS 5,4İstismar yokEPSS %1okta · imprivata privileged access management20 Tem 2023
- CVE-2025-6603321İzleyin
Improper Memory Cleanup in the Okta Java SDK
OrtaCVSS 5,3İstismar yokEPSS %0okta · java management sdk10 Ara 2025