Forgerock

Access Management

12 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.1%
  • Published 29.10.2024 16:15:04
  • Last modified 08.11.2024 15:38:56

An Open-Redirect vulnerability exists in PingAM where well-crafted requests may cause improper validation of redirect URLs. This could allow an attacker to redirect end-users to malicious sites under their control, simplifying phishing attacks

  • EPSS 0.04%
  • Published 27.03.2024 18:15:08
  • Last modified 14.04.2025 17:15:26

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ForgeRock Access Management allows Authorization Bypass. This issue affects access management: before 7.3.0, before 7.2.1, before 7.1.4, through 7.0.2.

  • EPSS 0.09%
  • Published 14.04.2023 15:15:07
  • Last modified 21.11.2024 07:20:10

Improper Authorization vulnerability in ForgeRock Inc. Access Management allows Authentication Bypass. This issue affects Access Management: from 6.5.0 through 7.2.0.

  • EPSS 0.24%
  • Published 27.10.2022 17:15:09
  • Last modified 21.11.2024 06:50:49

It may be possible to gain some details of the deployment through a well-crafted attack. This may allow that data to be used to probe internal network services.

  • EPSS 0.15%
  • Published 27.10.2022 17:15:09
  • Last modified 21.11.2024 06:50:49

An attacker can use the unrestricted LDAP queries to determine configuration entries

  • EPSS 0.91%
  • Published 14.02.2022 22:15:07
  • Last modified 21.11.2024 06:37:08

Missing access control in ForgeRock Access Management 7.1.0 and earlier versions on all platforms allows remote unauthenticated attackers to hijack sessions, including potentially admin-level sessions. This issue affects: ForgeRock Access Management ...

  • EPSS 0.53%
  • Published 25.08.2021 21:15:08
  • Last modified 21.11.2024 06:14:44

In ForgeRock Access Management (AM) before 7.0.2, the SAML2 implementation allows XML injection, potentially enabling a fraudulent SAML 2.0 assertion.

  • EPSS 0.63%
  • Published 25.08.2021 21:15:06
  • Last modified 21.11.2024 06:14:44

ForgeRock Access Management (AM) before 7.0.2, when configured with Active Directory as the Identity Store, has an authentication-bypass issue.

Warning Exploit
  • EPSS 94.39%
  • Published 22.07.2021 18:15:23
  • Last modified 14.03.2025 16:45:41

ForgeRock AM server before 7.0 has a Java deserialization vulnerability in the jato.pageSession parameter on multiple pages. The exploitation does not require authentication, and remote code execution can be triggered by sending a single crafted /ccv...

  • EPSS 0.2%
  • Published 19.06.2019 22:15:13
  • Last modified 21.11.2024 03:12:41

OAuth 2.0 Authorization Server of ForgeRock Access Management (OpenAM) 13.5.0-13.5.1 and Access Management (AM) 5.0.0-5.1.1 does not correctly validate redirect_uri for some invalid requests, which allows attackers to perform phishing via an unvalida...