Forgerock
Forgerock Openam: vulnerabilidades y CVE
Forgerock Openam tiene 21 vulnerabilidades publicadas, 15 de ellas en los últimos 12 meses. 7 son críticas y 1 figuran en el catálogo de explotación activa de CISA.
CVE21
Últimos 12 meses15
Críticas7
Explotadas activamente1
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2021-35464 | Crítica (9.8) | 100% | ⚠ Explotación activa | 22 jul 2021 | ForgeRock AM server before 7.0 has a Java deserialization vulnerability in the jato.pageSession parameter on multiple pages. The exploitation does not require authentication, and remote code execution can be triggered… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-62379 | Crítica (9.8) | 1.1% | — | 15 sept 2026 | Open Access Management (OpenAM) is an access management solution. Prior to 16.1.2, the pre-authentication /authservice PLL endpoint accepts a CustomCallback XML element whose className value selects an arbitrary Java… |
| CVE-2026-62280 | Media (6.1) | 0.33% | — | 15 sept 2026 | Open Access Management (OpenAM) is an access management solution. From 13.0.0 until 16.1.2, the OAuth2 authorize endpoint's display=wap consent page reflects request-derived values through ConsentRequiredResource and… |
| CVE-2026-62263 | Crítica (9.2) | 0.86% | — | 15 sept 2026 | Open Access Management (OpenAM) is an access management solution. Prior to 16.1.2, WebAuthnAuthentication.deserialize applies an ObjectInputFilter that allows every serialized object at depth greater than 1 and… |
| CVE-2026-53660 | Alta (7.4) | 0.41% | — | 15 sept 2026 | Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the default configuration initializes the iPlanetDirectoryPro SSO cookie with HttpOnly disabled and without a protective SameSite… |
| CVE-2026-48717 | Crítica (9.1) | 0.53% | — | 15 sept 2026 | Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, AuthorizationCodeGrantTypeHandler requires a code_verifier only when the realm-wide codeVerifierEnforced setting is enabled, even when… |
| CVE-2026-47426 | Alta (7.6) | 0.55% | — | 15 sept 2026 | Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the private_key_jwt client authentication path uses ClientJwksResolverCache without reliably binding a cached jwks_uri resolver and… |
| CVE-2026-47424 | Alta (7.5) | 0.48% | — | 15 sept 2026 | Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, GroovySandboxValueFilter permits an authenticated server-side script author to escape the scripting sandbox despite the default class… |
| CVE-2026-46623 | Alta (7.4) | 0.67% | — | 15 sept 2026 | Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the OAuth2 authentication module updates an existing local account with profile attributes that can include userPassword and… |
| CVE-2026-46619 | Crítica (9.3) | 0.99% | — | 15 sept 2026 | Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, MSISDNValidation in the MSISDN authentication module concatenates the request-supplied MSISDN value into an LDAP search filter without… |
| CVE-2026-46498 | Alta (7.6) | 0.41% | — | 15 sept 2026 | Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, OAuthTokenStore reads caller-supplied token identifiers from the shared Core Token Store (CTS) without an OAuth-only namespace, and… |
| CVE-2026-45052 | Crítica (9.3) | 0.77% | — | 15 sept 2026 | Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the Liberty Web Services SOAP receiver permits unauthenticated remote requests to write persistent entries through SOAPReceiver and… |
| CVE-2026-45051 | Crítica (9.2) | 0.69% | — | 15 sept 2026 | Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, WebAuthnAuthentication loads a serialized AuthenticatorImpl object graph from the configured userAttribute through loadAuthenticators… |
| CVE-2026-45048 | Alta (8.5) | 0.43% | — | 15 sept 2026 | Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, SessionRequestHandler in the session management endpoint does not enforce ownership or privilege checks when a low-privileged… |
| CVE-2026-44793 | Alta (7) | 0.59% | — | 15 sept 2026 | Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, certain federation endpoints in a non-default clustered configuration inconsistently encode user-supplied parameters rendered into HTML… |
| CVE-2026-41573 | Alta (7.1) | 0.50% | — | 15 sept 2026 | Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, IdentityResourceV1.queryCollection() passes the _queryId parameter from /json/{realm}/users to CrestQuery with escapeQueryId disabled,… |
| CVE-2021-35464 | Crítica (9.8) | 100% | ⚠ Explotación activa | 22 jul 2021 | ForgeRock AM server before 7.0 has a Java deserialization vulnerability in the jato.pageSession parameter on multiple pages. The exploitation does not require authentication, and remote code execution can be triggered… |
| CVE-2021-29156 | Alta (7.5) | 77% | — | 25 mar 2021 | ForgeRock OpenAM before 13.5.1 allows LDAP injection via the Webfinger protocol. For example, an unauthenticated attacker can perform character-by-character retrieval of password hashes, or retrieve a session token or a… |
| CVE-2017-14395 | Media (6.1) | 0.79% | — | 19 jun 2019 | Auth 2.0 Authorization Server of ForgeRock Access Management (OpenAM) 13.5.0-13.5.1 and Access Management (AM) 5.0.0-5.1.1 does not correctly validate redirect_uri for some invalid requests, which allows attackers to… |
| CVE-2017-14394 | Media (6.1) | 0.79% | — | 19 jun 2019 | OAuth 2.0 Authorization Server of ForgeRock Access Management (OpenAM) 13.5.0-13.5.1 and Access Management (AM) 5.0.0-5.1.1 does not correctly validate redirect_uri for some invalid requests, which allows attackers to… |
| CVE-2016-10097 | Alta (7.5) | 2.5% | — | 2 ene 2017 | XML External Entity (XXE) Vulnerability in /SSOPOST/metaAlias/%realm%/idpv2 in OpenAM - Access Management 10.1.0 allows remote attackers to read arbitrary files via the SAMLRequest parameter. |
| CVE-2014-7246 | Baja (3.5) | 1.1% | — | 14 nov 2014 | The Core Server in OpenAM 9.5.3 through 9.5.5, 10.0.0 through 10.0.2, 10.1.0-Xpress, and 11.0.0 through 11.0.2, when deployed on a multi-server network, allows remote authenticated users to cause a denial of service… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.