Vulnerabilities
Vulnerable Software
An Open-Redirect vulnerability exists in PingAM where well-crafted requests may cause improper validation of redirect URLs. This could allow an attacker to redirect end-users to malicious sites under their control, simplifying phishing attacks
CVSS Score
6.1
EPSS Score
0.001
Published
2024-10-29
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ForgeRock Access Management allows Authorization Bypass. This issue affects access management: before 7.3.0, before 7.2.1, before 7.1.4, through 7.0.2.
CVSS Score
8.1
EPSS Score
0.0
Published
2024-03-27
Improper Authorization vulnerability in ForgeRock Inc. Access Management allows Authentication Bypass. This issue affects Access Management: from 6.5.0 through 7.2.0.
CVSS Score
9.8
EPSS Score
0.001
Published
2023-04-14
It may be possible to gain some details of the deployment through a well-crafted attack. This may allow that data to be used to probe internal network services.
CVSS Score
6.5
EPSS Score
0.002
Published
2022-10-27
An attacker can use the unrestricted LDAP queries to determine configuration entries
CVSS Score
7.1
EPSS Score
0.002
Published
2022-10-27
Missing access control in ForgeRock Access Management 7.1.0 and earlier versions on all platforms allows remote unauthenticated attackers to hijack sessions, including potentially admin-level sessions. This issue affects: ForgeRock Access Management 7.1 versions prior to 7.1.1; 6.5 versions prior to 6.5.4; all previous versions.
CVSS Score
9.6
EPSS Score
0.009
Published
2022-02-14
In ForgeRock Access Management (AM) before 7.0.2, the SAML2 implementation allows XML injection, potentially enabling a fraudulent SAML 2.0 assertion.
CVSS Score
9.8
EPSS Score
0.005
Published
2021-08-25
ForgeRock Access Management (AM) before 7.0.2, when configured with Active Directory as the Identity Store, has an authentication-bypass issue.
CVSS Score
9.8
EPSS Score
0.006
Published
2021-08-25


Contact Us

Shodan ® - All rights reserved