Okta Privileged Access server agent (SFTD) versions 1.82.0 to 1.84.0 are affected by a privilege escalation vulnerability when the sudo command bundles feature is enabled. To remediate this vulnerability, upgrade the Okta Privileged Access server agent (SFTD) to version 1.87.1 or greater.
History

Fri, 22 Nov 2024 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Okta
Okta privileged Access Server Agent Sftd
CPEs cpe:2.3:a:okta:privileged_access_server_agent_sftd:*:*:*:*:*:*:*:*
Vendors & Products Okta
Okta privileged Access Server Agent Sftd
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 20 Nov 2024 22:45:00 +0000

Type Values Removed Values Added
Description Okta Privileged Access server agent (SFTD) versions 1.82.0 to 1.84.0 are affected by a privilege escalation vulnerability when the sudo command bundles feature is enabled. Okta Privileged Access server agent (SFTD) versions 1.82.0 to 1.84.0 are affected by a privilege escalation vulnerability when the sudo command bundles feature is enabled. To remediate this vulnerability, upgrade the Okta Privileged Access server agent (SFTD) to version 1.87.1 or greater.

Wed, 20 Nov 2024 22:30:00 +0000

Type Values Removed Values Added
Description Okta Privileged Access server agent (SFTD) versions 1.82.0 to 1.84.0 are affected by a privilege escalation vulnerability when the sudo command bundles feature is enabled.
Weaknesses CWE-20
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Okta

Published: 2024-11-20T22:23:15.230Z

Updated: 2024-11-22T15:25:43.803Z

Reserved: 2024-10-11T16:36:50.988Z

Link: CVE-2024-9875

cve-icon Vulnrichment

Updated: 2024-11-22T15:25:38.745Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-11-21T09:54:49.903

Modified: 2024-11-21T13:57:24.187

Link: CVE-2024-9875

cve-icon Redhat

No data.