Vulnerabilities
Vulnerable Software
Forgerock:  >> Access Management  Security Vulnerabilities
An Open-Redirect vulnerability exists in PingAM where well-crafted requests may cause improper validation of redirect URLs. This could allow an attacker to redirect end-users to malicious sites under their control, simplifying phishing attacks
CVSS Score
6.1
EPSS Score
0.001
Published
2024-10-29
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ForgeRock Access Management allows Authorization Bypass. This issue affects access management: before 7.3.0, before 7.2.1, before 7.1.4, through 7.0.2.
CVSS Score
8.1
EPSS Score
0.0
Published
2024-03-27
Improper Authorization vulnerability in ForgeRock Inc. Access Management allows Authentication Bypass. This issue affects Access Management: from 6.5.0 through 7.2.0.
CVSS Score
9.8
EPSS Score
0.001
Published
2023-04-14
It may be possible to gain some details of the deployment through a well-crafted attack. This may allow that data to be used to probe internal network services.
CVSS Score
6.5
EPSS Score
0.002
Published
2022-10-27
An attacker can use the unrestricted LDAP queries to determine configuration entries
CVSS Score
7.1
EPSS Score
0.001
Published
2022-10-27
Missing access control in ForgeRock Access Management 7.1.0 and earlier versions on all platforms allows remote unauthenticated attackers to hijack sessions, including potentially admin-level sessions. This issue affects: ForgeRock Access Management 7.1 versions prior to 7.1.1; 6.5 versions prior to 6.5.4; all previous versions.
CVSS Score
9.6
EPSS Score
0.009
Published
2022-02-14
In ForgeRock Access Management (AM) before 7.0.2, the SAML2 implementation allows XML injection, potentially enabling a fraudulent SAML 2.0 assertion.
CVSS Score
9.8
EPSS Score
0.005
Published
2021-08-25
ForgeRock Access Management (AM) before 7.0.2, when configured with Active Directory as the Identity Store, has an authentication-bypass issue.
CVSS Score
9.8
EPSS Score
0.006
Published
2021-08-25
CVE-2021-35464
Known exploited
ForgeRock AM server before 7.0 has a Java deserialization vulnerability in the jato.pageSession parameter on multiple pages. The exploitation does not require authentication, and remote code execution can be triggered by sending a single crafted /ccversion/* request to the server. The vulnerability exists due to the usage of Sun ONE Application Framework (JATO) found in versions of Java 8 or earlier
CVSS Score
9.8
EPSS Score
0.944
Published
2021-07-22
OAuth 2.0 Authorization Server of ForgeRock Access Management (OpenAM) 13.5.0-13.5.1 and Access Management (AM) 5.0.0-5.1.1 does not correctly validate redirect_uri for some invalid requests, which allows attackers to perform phishing via an unvalidated redirect.
CVSS Score
6.1
EPSS Score
0.002
Published
2019-06-19


Contact Us

Shodan ® - All rights reserved