Vulnerabilities
Vulnerable Software
Forgerock:  >> Access Management  Security Vulnerabilities
Auth 2.0 Authorization Server of ForgeRock Access Management (OpenAM) 13.5.0-13.5.1 and Access Management (AM) 5.0.0-5.1.1 does not correctly validate redirect_uri for some invalid requests, which allows attackers to execute a script in the user's browser via reflected XSS.
CVSS Score
6.1
EPSS Score
0.003
Published
2019-06-19
The REST APIs in ForgeRock AM before 5.5.0 include SSOToken IDs as part of the URL, which allows attackers to obtain sensitive information by finding an ID value in a log file.
CVSS Score
6.5
EPSS Score
0.003
Published
2018-02-21


Contact Us

Shodan ® - All rights reserved