VendorsForgeRockaccess_managementany version
Vulnerabilities

ForgeRock Access Management any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

11CVEs
CVE-2021-35464
ForgeRock AM server before 7.0 has a Java deserialization vulnerability in the jato.pageSession parameter on multiple pages. The exploitation does not require authentication, and remote code execution can be triggered by sending a single crafted /ccversion/* request to the server. The vulnerability exists due to the usage of Sun ONE Application Framework (JATO) found in versions of Java 8 or earlier
Published 2021-07-22 · Analyzed
10.0KEV1 PoCEPSS 1.000
CVE-2021-37154
In ForgeRock Access Management (AM) before 7.0.2, the SAML2 implementation allows XML injection, potentially enabling a fraudulent SAML 2.0 assertion.
Published 2021-08-25 · Modified
10.0EPSS 0.014
CVE-2021-37153
ForgeRock Access Management (AM) before 7.0.2, when configured with Active Directory as the Identity Store, has an authentication-bypass issue.
Published 2021-08-25 · Modified
9.8EPSS 0.012
CVE-2022-3748
Improper authorization that can lead to account impersonation
Published 2023-04-14 · Modified
9.8EPSS 0.009
CVE-2023-0582
Path Traversal in ForgeRock Access Managment
Published 2024-03-27 · Modified
9.8EPSS 0.008
CVE-2022-24670
Any user can run unrestricted LDAP queries against a configuration endpoint
Published 2022-10-27 · Modified
7.1EPSS 0.006
CVE-2018-7272
The REST APIs in ForgeRock AM before 5.5.0 include SSOToken IDs as part of the URL, which allows attackers to obtain sensitive information by finding an ID value in a log file.
Published 2018-02-21 · Modified
6.5EPSS 0.009
CVE-2022-24669
Anonymous users can register / de-register for configuration change notifications
Published 2022-10-27 · Modified
6.5EPSS 0.004
CVE-2017-14394
OAuth 2.0 Authorization Server of ForgeRock Access Management (OpenAM) 13.5.0-13.5.1 and Access Management (AM) 5.0.0-5.1.1 does not correctly validate redirect_uri for some invalid requests, which allows attackers to perform phishing via an unvalidated redirect.
Published 2019-06-19 · Modified
6.1EPSS 0.008
CVE-2017-14395
Auth 2.0 Authorization Server of ForgeRock Access Management (OpenAM) 13.5.0-13.5.1 and Access Management (AM) 5.0.0-5.1.1 does not correctly validate redirect_uri for some invalid requests, which allows attackers to execute a script in the user's browser via reflected XSS.
Published 2019-06-19 · Modified
6.1EPSS 0.008
CVE-2024-25566
Open Redirect in PingAM
Published 2024-10-29 · Analyzed
6.1EPSS 0.002