QID 92011
Date Published: 2023-06-07
QID 92011: Okta Advanced Server Access Client (ScaleFT) Command Injection Vulnerability
Okta Advanced Server Access (ScaleFT) is a tool allowing organizations to secure access to SSH and RDP servers via a centralized authentication method.
Affected Versions:
Okta Advanced Server Access Client for Windows versions 1.13.1 through 1.68.1.
QID Detection Logic (Authenticated):
For Windows Operating System, this QID checks for the vulnerable version of ScaleFT by checking the uninstall registry keys.
Okta Advanced Server Access Client versions 1.13.1 through 1.68.1 are vulnerable to command injection due to the third-party library web browser.
Solution
The vendor has released updates to resolve this issue.
Customers are advised to visit Okta Advanced Server Access Client for latest version and more information on this vulnerability.
Vendor References
- Okta Advanced Server Access Client -
trust.okta.com/security-advisories/okta-advanced-server-access-client-cve-2023-0093/
CVEs related to QID 92011
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Okta Advanced Server Access Client |
|