CVE-2021-22530
HIGHDescription
A vulnerability identified in NetIQ Advance Authentication that doesn't enforce account lockout when brute force attack is performed on API based login. This issue may lead to user account compromise if successful or may impact server performance. This issue impacts all NetIQ Advance Authentication before 6.3.5.1
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| microfocus | netiq_advanced_authentication |
| microfocus | netiq_advanced_authentication |
| microfocus | netiq_advanced_authentication |
| microfocus | netiq_advanced_authentication |
| microfocus | netiq_advanced_authentication |
| microfocus | netiq_advanced_authentication |
| microfocus | netiq_advanced_authentication |
| microfocus | netiq_advanced_authentication |
References
Frequently Asked Questions
What is CVE-2021-22530? +
How severe is CVE-2021-22530? +
What products are affected by CVE-2021-22530? +
How do I check if I'm vulnerable to CVE-2021-22530? +
Related Vulnerabilities
A Zigbee Radio Co-Processor (RCP), which is using SiLabs EmberZNet Zigbee stack, was unable to send messages to the host …
Improper locking vulnerability in Softing Industrial Automation GmbH gateways allows infected memory and/or resource leak exposure.This issue affects smartLink HW-PN: …
In the Linux kernel, the following vulnerability has been resolved: cifs: Fix locking usage for tcon fields We used to …
In the Linux kernel, the following vulnerability has been resolved: nfc: llcp: add missing return after LLCP_CLOSED checks In nfc_llcp_recv_hdlc() …
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix racy issue from session lookup and expire Increment …
A memory corruption issue was addressed with improved lock state checking. This issue is fixed in iOS 18.7.2 and iPadOS …