CVE-2024-25566
- EPSS 0.1%
- Published 29.10.2024 16:15:04
- Last modified 08.11.2024 15:38:56
An Open-Redirect vulnerability exists in PingAM where well-crafted requests may cause improper validation of redirect URLs. This could allow an attacker to redirect end-users to malicious sites under their control, simplifying phishing attacks
CVE-2023-0582
- EPSS 0.04%
- Published 27.03.2024 18:15:08
- Last modified 14.04.2025 17:15:26
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ForgeRock Access Management allows Authorization Bypass. This issue affects access management: before 7.3.0, before 7.2.1, before 7.1.4, through 7.0.2.
CVE-2022-3748
- EPSS 0.09%
- Published 14.04.2023 15:15:07
- Last modified 21.11.2024 07:20:10
Improper Authorization vulnerability in ForgeRock Inc. Access Management allows Authentication Bypass. This issue affects Access Management: from 6.5.0 through 7.2.0.
CVE-2022-24669
- EPSS 0.24%
- Published 27.10.2022 17:15:09
- Last modified 21.11.2024 06:50:49
It may be possible to gain some details of the deployment through a well-crafted attack. This may allow that data to be used to probe internal network services.
CVE-2022-24670
- EPSS 0.15%
- Published 27.10.2022 17:15:09
- Last modified 21.11.2024 06:50:49
An attacker can use the unrestricted LDAP queries to determine configuration entries
CVE-2021-4201
- EPSS 0.91%
- Published 14.02.2022 22:15:07
- Last modified 21.11.2024 06:37:08
Missing access control in ForgeRock Access Management 7.1.0 and earlier versions on all platforms allows remote unauthenticated attackers to hijack sessions, including potentially admin-level sessions. This issue affects: ForgeRock Access Management ...
- EPSS 0.53%
- Published 25.08.2021 21:15:08
- Last modified 21.11.2024 06:14:44
In ForgeRock Access Management (AM) before 7.0.2, the SAML2 implementation allows XML injection, potentially enabling a fraudulent SAML 2.0 assertion.
CVE-2021-37153
- EPSS 0.63%
- Published 25.08.2021 21:15:06
- Last modified 21.11.2024 06:14:44
ForgeRock Access Management (AM) before 7.0.2, when configured with Active Directory as the Identity Store, has an authentication-bypass issue.
- EPSS 94.39%
- Published 22.07.2021 18:15:23
- Last modified 14.03.2025 16:45:41
ForgeRock AM server before 7.0 has a Java deserialization vulnerability in the jato.pageSession parameter on multiple pages. The exploitation does not require authentication, and remote code execution can be triggered by sending a single crafted /ccv...
CVE-2017-14394
- EPSS 0.2%
- Published 19.06.2019 22:15:13
- Last modified 21.11.2024 03:12:41
OAuth 2.0 Authorization Server of ForgeRock Access Management (OpenAM) 13.5.0-13.5.1 and Access Management (AM) 5.0.0-5.1.1 does not correctly validate redirect_uri for some invalid requests, which allows attackers to perform phishing via an unvalida...