Access Management
Forgerock · 12 CVEs
Open Redirect in PingAM
Oct 29, 2024
Path Traversal in ForgeRock Access Managment
Mar 27, 2024
Improper authorization that can lead to account impersonation
Apr 14, 2023
Anonymous users can register / de-register for configuration change notifications
Oct 27, 2022
Any user can run unrestricted LDAP queries against a configuration endpoint
Oct 27, 2022
Pre-authentication session hijacking
Feb 14, 2022
ForgeRock Access Management (AM) before 7.0.2, when configured with Active Directory as the Identity Store, has an auth…
Aug 25, 2021
In ForgeRock Access Management (AM) before 7.0.2, the SAML2 implementation allows XML injection, potentially enabling a…
Aug 25, 2021
ForgeRock AM server before 7.0 has a Java deserialization vulnerability in the jato.pageSession parameter on multiple p…
Jul 22, 2021
Auth 2.0 Authorization Server of ForgeRock Access Management (OpenAM) 13.5.0-13.5.1 and Access Management (AM) 5.0.0-5.…
Jun 19, 2019
OAuth 2.0 Authorization Server of ForgeRock Access Management (OpenAM) 13.5.0-13.5.1 and Access Management (AM) 5.0.0-5…
Jun 19, 2019
The REST APIs in ForgeRock AM before 5.5.0 include SSOToken IDs as part of the URL, which allows attackers to obtain se…
Feb 21, 2018
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2024-25566 | Open Redirect in PingAM | MEDIUM | 0.23% | Oct 29, 2024 |
| CVE-2023-0582 | Path Traversal in ForgeRock Access Managment | CRITICAL | 0.78% | Mar 27, 2024 |
| CVE-2022-3748 | Improper authorization that can lead to account impersonation | CRITICAL | 0.91% | Apr 14, 2023 |
| CVE-2022-24669 | Anonymous users can register / de-register for configuration change notifications | MEDIUM | 0.40% | Oct 27, 2022 |
| CVE-2022-24670 | Any user can run unrestricted LDAP queries against a configuration endpoint | HIGH | 0.60% | Oct 27, 2022 |
| CVE-2021-4201 | Pre-authentication session hijacking | CRITICAL | 1.99% | Feb 14, 2022 |
| CVE-2021-37153 | ForgeRock Access Management (AM) before 7.0.2, when configured with Active Directory as the Identity Store, has an authentication-bypass issue. | CRITICAL | 1.19% | Aug 25, 2021 |
| CVE-2021-37154 | In ForgeRock Access Management (AM) before 7.0.2, the SAML2 implementation allows XML injection, potentially enabling a fraudulent SAML 2.0 assertion. | CRITICAL | 1.36% | Aug 25, 2021 |
| CVE-2021-35464 KEV | ForgeRock AM server before 7.0 has a Java deserialization vulnerability in the jato.pageSession parameter on multiple pages. The exploitation does not require… | CRITICAL | 100.00% | Jul 22, 2021 |
| CVE-2017-14395 | Auth 2.0 Authorization Server of ForgeRock Access Management (OpenAM) 13.5.0-13.5.1 and Access Management (AM) 5.0.0-5.1.1 does not correctly validate redirect… | MEDIUM | 0.79% | Jun 19, 2019 |
| CVE-2017-14394 | OAuth 2.0 Authorization Server of ForgeRock Access Management (OpenAM) 13.5.0-13.5.1 and Access Management (AM) 5.0.0-5.1.1 does not correctly validate redirec… | MEDIUM | 0.79% | Jun 19, 2019 |
| CVE-2018-7272 | The REST APIs in ForgeRock AM before 5.5.0 include SSOToken IDs as part of the URL, which allows attackers to obtain sensitive information by finding an ID val… | MEDIUM | 0.86% | Feb 21, 2018 |
Showing 1 to 12 of 12 CVEs