CVE-2021-22530

A vulnerability identified in NetIQ Advance Authentication that doesn't enforce account lockout when brute force attack is performed on API based login. This issue may lead to user account compromise if successful or may impact server performance. This issue impacts all NetIQ Advance Authentication before 6.3.5.1
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.2 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:L
OpenTextCNA
8.2 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:L
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 28%
VendorProductVersion
microfocusnetiq_advanced_authentication
𝑥
< 6.3
microfocusnetiq_advanced_authentication
6.3
microfocusnetiq_advanced_authentication
6.3:sp1
microfocusnetiq_advanced_authentication
6.3:sp2
microfocusnetiq_advanced_authentication
6.3:sp3
microfocusnetiq_advanced_authentication
6.3:sp4
microfocusnetiq_advanced_authentication
6.3:sp4_patch1
microfocusnetiq_advanced_authentication
6.3:sp5
𝑥
= Vulnerable software versions