Vulnerabilities
Vulnerable Software
An Open-Redirect vulnerability exists in PingAM where well-crafted requests may cause improper validation of redirect URLs. This could allow an attacker to redirect end-users to malicious sites under their control, simplifying phishing attacks
CVSS Score
6.1
EPSS Score
0.001
Published
2024-10-29
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ForgeRock Access Management allows Authorization Bypass. This issue affects access management: before 7.3.0, before 7.2.1, before 7.1.4, through 7.0.2.
CVSS Score
8.1
EPSS Score
0.0
Published
2024-03-27
In ForgeRock Access Management (AM) before 7.0.2, the SAML2 implementation allows XML injection, potentially enabling a fraudulent SAML 2.0 assertion.
CVSS Score
9.8
EPSS Score
0.005
Published
2021-08-25
CVE-2021-35464
Known exploited
ForgeRock AM server before 7.0 has a Java deserialization vulnerability in the jato.pageSession parameter on multiple pages. The exploitation does not require authentication, and remote code execution can be triggered by sending a single crafted /ccversion/* request to the server. The vulnerability exists due to the usage of Sun ONE Application Framework (JATO) found in versions of Java 8 or earlier
CVSS Score
9.8
EPSS Score
0.944
Published
2021-07-22


Contact Us

Shodan ® - All rights reserved