« Volver al listado

Forgerock

Forgerock Openam: vulnerabilidades y CVE

Forgerock Openam tiene 21 vulnerabilidades publicadas, 15 de ellas en los últimos 12 meses. 7 son críticas y 1 figuran en el catálogo de explotación activa de CISA.

CVE21
Últimos 12 meses15
Críticas7
Explotadas activamente1

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

🔴 Explotadas activamente (CISA KEV)

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2021-35464Crítica (9.8)100%⚠ Explotación activa22 jul 2021
ForgeRock AM server before 7.0 has a Java deserialization vulnerability in the jato.pageSession parameter on multiple pages. The exploitation does not require authentication, and remote code execution can be triggered…

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-62379Crítica (9.8)1.1%—15 sept 2026
Open Access Management (OpenAM) is an access management solution. Prior to 16.1.2, the pre-authentication /authservice PLL endpoint accepts a CustomCallback XML element whose className value selects an arbitrary Java…
CVE-2026-62280Media (6.1)0.33%—15 sept 2026
Open Access Management (OpenAM) is an access management solution. From 13.0.0 until 16.1.2, the OAuth2 authorize endpoint's display=wap consent page reflects request-derived values through ConsentRequiredResource and…
CVE-2026-62263Crítica (9.2)0.86%—15 sept 2026
Open Access Management (OpenAM) is an access management solution. Prior to 16.1.2, WebAuthnAuthentication.deserialize applies an ObjectInputFilter that allows every serialized object at depth greater than 1 and…
CVE-2026-53660Alta (7.4)0.41%—15 sept 2026
Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the default configuration initializes the iPlanetDirectoryPro SSO cookie with HttpOnly disabled and without a protective SameSite…
CVE-2026-48717Crítica (9.1)0.53%—15 sept 2026
Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, AuthorizationCodeGrantTypeHandler requires a code_verifier only when the realm-wide codeVerifierEnforced setting is enabled, even when…
CVE-2026-47426Alta (7.6)0.55%—15 sept 2026
Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the private_key_jwt client authentication path uses ClientJwksResolverCache without reliably binding a cached jwks_uri resolver and…
CVE-2026-47424Alta (7.5)0.48%—15 sept 2026
Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, GroovySandboxValueFilter permits an authenticated server-side script author to escape the scripting sandbox despite the default class…
CVE-2026-46623Alta (7.4)0.67%—15 sept 2026
Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the OAuth2 authentication module updates an existing local account with profile attributes that can include userPassword and…
CVE-2026-46619Crítica (9.3)0.99%—15 sept 2026
Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, MSISDNValidation in the MSISDN authentication module concatenates the request-supplied MSISDN value into an LDAP search filter without…
CVE-2026-46498Alta (7.6)0.41%—15 sept 2026
Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, OAuthTokenStore reads caller-supplied token identifiers from the shared Core Token Store (CTS) without an OAuth-only namespace, and…
CVE-2026-45052Crítica (9.3)0.77%—15 sept 2026
Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the Liberty Web Services SOAP receiver permits unauthenticated remote requests to write persistent entries through SOAPReceiver and…
CVE-2026-45051Crítica (9.2)0.69%—15 sept 2026
Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, WebAuthnAuthentication loads a serialized AuthenticatorImpl object graph from the configured userAttribute through loadAuthenticators…
CVE-2026-45048Alta (8.5)0.43%—15 sept 2026
Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, SessionRequestHandler in the session management endpoint does not enforce ownership or privilege checks when a low-privileged…
CVE-2026-44793Alta (7)0.59%—15 sept 2026
Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, certain federation endpoints in a non-default clustered configuration inconsistently encode user-supplied parameters rendered into HTML…
CVE-2026-41573Alta (7.1)0.50%—15 sept 2026
Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, IdentityResourceV1.queryCollection() passes the _queryId parameter from /json/{realm}/users to CrestQuery with escapeQueryId disabled,…
CVE-2021-35464Crítica (9.8)100%⚠ Explotación activa22 jul 2021
ForgeRock AM server before 7.0 has a Java deserialization vulnerability in the jato.pageSession parameter on multiple pages. The exploitation does not require authentication, and remote code execution can be triggered…
CVE-2021-29156Alta (7.5)77%—25 mar 2021
ForgeRock OpenAM before 13.5.1 allows LDAP injection via the Webfinger protocol. For example, an unauthenticated attacker can perform character-by-character retrieval of password hashes, or retrieve a session token or a…
CVE-2017-14395Media (6.1)0.79%—19 jun 2019
Auth 2.0 Authorization Server of ForgeRock Access Management (OpenAM) 13.5.0-13.5.1 and Access Management (AM) 5.0.0-5.1.1 does not correctly validate redirect_uri for some invalid requests, which allows attackers to…
CVE-2017-14394Media (6.1)0.79%—19 jun 2019
OAuth 2.0 Authorization Server of ForgeRock Access Management (OpenAM) 13.5.0-13.5.1 and Access Management (AM) 5.0.0-5.1.1 does not correctly validate redirect_uri for some invalid requests, which allows attackers to…
CVE-2016-10097Alta (7.5)2.5%—2 ene 2017
XML External Entity (XXE) Vulnerability in /SSOPOST/metaAlias/%realm%/idpv2 in OpenAM - Access Management 10.1.0 allows remote attackers to read arbitrary files via the SAMLRequest parameter.
CVE-2014-7246Baja (3.5)1.1%—14 nov 2014
The Core Server in OpenAM 9.5.3 through 9.5.5, 10.0.0 through 10.0.2, 10.1.0-Xpress, and 11.0.0 through 11.0.2, when deployed on a multi-server network, allows remote authenticated users to cause a denial of service…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1190 Exploit Public-Facing Application7
  2. T1059 Command and Scripting Interpreter5
  3. T1210 Exploitation of Remote Services5
  4. T1005 Data from Local System2
  5. T1078 Valid Accounts2
  6. T1078.001 Default Accounts2

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Forgerock