Forgerock / Openam
6 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2021-35464 KEV | ForgeRock AM server before 7.0 has a Java deserialization vulnerability in the jato.pageSession parameter on multiple pages. The exploitation does not require… | CRITICAL | 9.8 | Jul 22, 2021 |
| CVE-2021-29156 | ForgeRock OpenAM before 13.5.1 allows LDAP injection via the Webfinger protocol. For example, an unauthenticated attacker can perform character-by-character re… | HIGH | 7.5 | Mar 25, 2021 |
| CVE-2017-14395 | Auth 2.0 Authorization Server of ForgeRock Access Management (OpenAM) 13.5.0-13.5.1 and Access Management (AM) 5.0.0-5.1.1 does not correctly validate redirect… | MEDIUM | 6.1 | Jun 19, 2019 |
| CVE-2017-14394 | OAuth 2.0 Authorization Server of ForgeRock Access Management (OpenAM) 13.5.0-13.5.1 and Access Management (AM) 5.0.0-5.1.1 does not correctly validate redirec… | MEDIUM | 6.1 | Jun 19, 2019 |
| CVE-2016-10097 | XML External Entity (XXE) Vulnerability in /SSOPOST/metaAlias/%realm%/idpv2 in OpenAM - Access Management 10.1.0 allows remote attackers to read arbitrary file… | HIGH | 7.5 | Jan 2, 2017 |
| CVE-2014-7246 | The Core Server in OpenAM 9.5.3 through 9.5.5, 10.0.0 through 10.0.2, 10.1.0-Xpress, and 11.0.0 through 11.0.2, when deployed on a multi-server network, allows… | LOW | 3.5 | Nov 14, 2014 |
Showing 1 to 6 of 6 CVEs