Show filters
22 Total Results
Displaying 1-10 of 22
Sort by:
Attacker Value
Very High

Pre-auth RCE in ForgeRock Access Manager (CVE-2021-35464)

Disclosure Date: July 22, 2021 (last updated October 07, 2023)
ForgeRock AM server before 7.0 has a Java deserialization vulnerability in the jato.pageSession parameter on multiple pages. The exploitation does not require authentication, and remote code execution can be triggered by sending a single crafted /ccversion/* request to the server. The vulnerability exists due to the usage of Sun ONE Application Framework (JATO) found in versions of Java 8 or earlier
Attacker Value
High

CVE-2023-0339

Disclosure Date: February 28, 2023 (last updated December 22, 2024)
Relative Path Traversal vulnerability in ForgeRock Access Management Web Policy Agent allows Authentication Bypass. This issue affects Access Management Web Policy Agent: all versions up to 5.10.1
Attacker Value
Unknown

CVE-2024-25566

Disclosure Date: October 29, 2024 (last updated November 09, 2024)
An Open-Redirect vulnerability exists in PingAM where well-crafted requests may cause improper validation of redirect URLs. This could allow an attacker to redirect end-users to malicious sites under their control, simplifying phishing attacks
Attacker Value
Unknown

CVE-2023-0582

Disclosure Date: March 27, 2024 (last updated April 02, 2024)
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ForgeRock Access Management allows Authorization Bypass. This issue affects access management: before 7.3.0, before 7.2.1, before 7.1.4, through 7.0.2.
0
Attacker Value
Unknown

CVE-2022-3748

Disclosure Date: April 14, 2023 (last updated November 08, 2023)
Improper Authorization vulnerability in ForgeRock Inc. Access Management allows Authentication Bypass. This issue affects Access Management: from 6.5.0 through 7.2.0.
Attacker Value
Unknown

CVE-2023-1656

Disclosure Date: March 29, 2023 (last updated November 08, 2023)
Cleartext Transmission of Sensitive Information vulnerability in ForgeRock Inc. OpenIDM and Java Remote Connector Server (RCS) LDAP Connector on Windows, MacOS, Linux allows Remote Services with Stolen Credentials.This issue affects OpenIDM and Java Remote Connector Server (RCS): from 1.5.20.9 through 1.5.20.13.
Attacker Value
Unknown

CVE-2023-0511

Disclosure Date: February 28, 2023 (last updated November 08, 2023)
Relative Path Traversal vulnerability in ForgeRock Access Management Java Policy Agent allows Authentication Bypass. This issue affects Access Management Java Policy Agent: all versions up to 5.10.1
Attacker Value
Unknown

CVE-2022-24669

Disclosure Date: October 20, 2022 (last updated December 22, 2024)
It may be possible to gain some details of the deployment through a well-crafted attack. This may allow that data to be used to probe internal network services.
Attacker Value
Unknown

CVE-2022-24670

Disclosure Date: October 20, 2022 (last updated December 22, 2024)
An attacker can use the unrestricted LDAP queries to determine configuration entries
Attacker Value
Unknown

CVE-2022-0143

Disclosure Date: September 19, 2022 (last updated October 08, 2023)
When the LDAP connector is started with StartTLS configured, unauthenticated access is granted. This issue affects: all versions of the LDAP connector prior to 1.5.20.9. The LDAP connector is bundled with Identity Management (IDM) and Remote Connector Server (RCS)