Forgerock
Forgerock Access Management: vulnerabilidades y CVE
Forgerock Access Management tiene 12 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 6 son críticas y 1 figuran en el catálogo de explotación activa de CISA.
CVE12
Últimos 12 meses0
Críticas6
Explotadas activamente1
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2021-35464 | Crítica (9.8) | 100% | ⚠ Explotación activa | 22 jul 2021 | ForgeRock AM server before 7.0 has a Java deserialization vulnerability in the jato.pageSession parameter on multiple pages. The exploitation does not require authentication, and remote code execution can be triggered… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2024-25566 | Media (5.1) | 0.23% | — | 29 oct 2024 | An Open-Redirect vulnerability exists in PingAM where well-crafted requests may cause improper validation of redirect URLs. This could allow an attacker to redirect end-users to malicious sites under their control,… |
| CVE-2023-0582 | Crítica (9.8) | 0.78% | — | 27 mar 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ForgeRock Access Management allows Authorization Bypass. This issue affects access management: before 7.3.0, before 7.2.1,… |
| CVE-2022-3748 | Crítica (9.8) | 0.91% | — | 14 abr 2023 | Improper Authorization vulnerability in ForgeRock Inc. Access Management allows Authentication Bypass. This issue affects Access Management: from 6.5.0 through 7.2.0. |
| CVE-2022-24670 | Media (6.5) | 0.60% | — | 27 oct 2022 | An attacker can use the unrestricted LDAP queries to determine configuration entries |
| CVE-2022-24669 | Media (6.5) | 0.40% | — | 27 oct 2022 | It may be possible to gain some details of the deployment through a well-crafted attack. This may allow that data to be used to probe internal network services. |
| CVE-2021-4201 | Crítica (9.8) | 2.0% | — | 14 feb 2022 | Missing access control in ForgeRock Access Management 7.1.0 and earlier versions on all platforms allows remote unauthenticated attackers to hijack sessions, including potentially admin-level sessions. This issue… |
| CVE-2021-37154 | Crítica (9.8) | 1.4% | — | 25 ago 2021 | In ForgeRock Access Management (AM) before 7.0.2, the SAML2 implementation allows XML injection, potentially enabling a fraudulent SAML 2.0 assertion. |
| CVE-2021-37153 | Crítica (9.8) | 1.2% | — | 25 ago 2021 | ForgeRock Access Management (AM) before 7.0.2, when configured with Active Directory as the Identity Store, has an authentication-bypass issue. |
| CVE-2021-35464 | Crítica (9.8) | 100% | ⚠ Explotación activa | 22 jul 2021 | ForgeRock AM server before 7.0 has a Java deserialization vulnerability in the jato.pageSession parameter on multiple pages. The exploitation does not require authentication, and remote code execution can be triggered… |
| CVE-2017-14395 | Media (6.1) | 0.79% | — | 19 jun 2019 | Auth 2.0 Authorization Server of ForgeRock Access Management (OpenAM) 13.5.0-13.5.1 and Access Management (AM) 5.0.0-5.1.1 does not correctly validate redirect_uri for some invalid requests, which allows attackers to… |
| CVE-2017-14394 | Media (6.1) | 0.79% | — | 19 jun 2019 | OAuth 2.0 Authorization Server of ForgeRock Access Management (OpenAM) 13.5.0-13.5.1 and Access Management (AM) 5.0.0-5.1.1 does not correctly validate redirect_uri for some invalid requests, which allows attackers to… |
| CVE-2018-7272 | Media (6.5) | 0.86% | — | 21 feb 2018 | The REST APIs in ForgeRock AM before 5.5.0 include SSOToken IDs as part of the URL, which allows attackers to obtain sensitive information by finding an ID value in a log file. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.