CVE-2021-22497

Advanced Authentication versions prior to 6.3 SP4 have a potential broken authentication due to improper session management issue.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
3.8 LOW
PHYSICAL
HIGH
HIGH
CVSS:3.1/AV:P/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N
microfocusCNA
3.8 LOW
PHYSICAL
HIGH
HIGH
CVSS:3.1/AV:P/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 47%
VendorProductVersion
microfocusnetiq_advanced_authentication
𝑥
< 6.3
microfocusnetiq_advanced_authentication
6.3
microfocusnetiq_advanced_authentication
6.3:sp1
microfocusnetiq_advanced_authentication
6.3:sp2
microfocusnetiq_advanced_authentication
6.3:sp3
𝑥
= Vulnerable software versions