Skip to content
OktaOKTA-0WGTR72

Okta On-Prem MFA Agent CVE-2021-45046 - Jan 26, 2022

UnratedCVE-2021-45046 · Published Jan 26, 2022

Apache Log4j2 2.15.0, as used in Okta On-Prem MFA Agent 1.4.6 (formerly Okta RSA SecurID Agent), contained an incomplete fix for CVE-2021-44228, which could allow attackers under certain conditions to craft malicious input data, resulting in a denial of service (DOS) attack. The new version includes Log4j 2.16.0 which fixes this issue by removing support for message lookup patterns and disabling JNDI functionality by default.

Okta advisory

Affected versions

The source does not list versions here. See the source advisory for affected products and fixes.
Details and references

More Okta advisories

All Okta
Advisory
Okta Access Gateway Advisory for CVE-2022-3602 and CVE-2022-3786 - Nov 1, 2022
UnratedNov 1, 2022
Okta Active Directory Agent CVE-2022-1697 - Sep 1, 2022
UnratedSep 1, 2022
Okta Advanced Server Access Client CVE-2022-1030 - Mar 21, 2022
UnratedMar 21, 2022
Okta Advanced Server Access Client CVE-2022-24295 - Feb 17, 2022
UnratedFeb 17, 2022
Okta RADIUS Server Agent CVE-2021-45105 - Jan 26, 2022
UnratedJan 26, 2022
Okta RADIUS Server Agent CVE-2021-45046 - Jan 26, 2022
UnratedJan 26, 2022

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.