Cross-Site Scripting Vulnerability in Imprivata's Privileged Access Management Solution
CVE-2021-45094

5.4MEDIUM

Key Information:

Vendor

Okta

Vendor
CVE Published:
20 July 2023

What is CVE-2021-45094?

Imprivata's Privileged Access Management, specifically version 2.3.202112051108, contains a Cross-Site Scripting (XSS) vulnerability that allows attackers to inject malicious scripts into web applications viewed by users. This exploit can lead to unauthorized access to sensitive data and user accounts, especially in environments where proper security controls are not implemented. Organizations utilizing this software should apply the recommended security patches or upgrades as soon as possible to mitigate potential risks and enhance their overall cybersecurity posture.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.