A Command Execution Vulnerability exists in IBM Sterling External Authentication Server 2.2.0, 2.3.01, 2.4.0, and 2.4.1 via an unspecified OS command, which could let a local malicious user execute arbitrary code.
| Software | From | Fixed in |
|---|---|---|
| ibm / sterling_external_authentication_server | 2.4.0 | 2.4.0.x |
| ibm / sterling_external_authentication_server | 2.3.01 | 2.3.01.x |
| ibm / sterling_external_authentication_server | 2.2.0 | 2.2.0.x |
| ibm / sterling_external_authentication_server | 2.4.1 | 2.4.1.x |