ForgeRock kayıtları
forgerock üreticisine ait 22 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 1 · %4,5
- Silahlaştırılmış
- 1 · %4,5
- Pre-auth RCE
- 2
- Düzeltme kaydı olan
- %4,5
- Yayından KEV’e ortanca
- 104 gün
Tekrar eden sınıflar
- CWE-601 URL Redirection to Untrusted Site ('Open Redirect')2
- CWE-23 Relative Path Traversal2
- CWE-284 Improper Access Control2
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
- CWE-20 Improper Input Validation2
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
22 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
99Hemen | CVE-2021-35464Silahlaştırılmış | ForgeRock AM server before 7.0 has a Java deserialization vulnerability in the jato.pageSession parameter on multiple pages.forgerock · access management · CWE-502 | Kritik9,8 | KEV | %100,0 | 22 Tem 2021 |
53Planlayın | CVE-2021-29156Kavram kanıtı | ForgeRock OpenAM before 13.5.1 allows LDAP injection via the Webfinger protocol.forgerock · openam · CWE-74 | Yüksek7,5 | — | %76,8 | 25 Mar 2021 |
40Planlayın | CVE-2021-4201İstismar yok | Pre-authentication session hijackingforgerock · access management · CWE-284 | Kritik9,8 | — | %2,0 | 14 Şub 2022 |
39İzleyin | CVE-2021-37154İstismar yok | In ForgeRock Access Management (AM) before 7.0.2, the SAML2 implementation allows XML injection, potentially enabling a fraudulent SAML 2.0 forgerock · access management · CWE-91 | Kritik9,8 | — | %1,4 | 25 Ağu 2021 |
39İzleyin | CVE-2021-37153İstismar yok | ForgeRock Access Management (AM) before 7.0.2, when configured with Active Directory as the Identity Store, has an authentication-bypass issforgerock · access management | Kritik9,8 | — | %1,2 | 25 Ağu 2021 |
39İzleyin | CVE-2023-0339İstismar yok | AM Web Policy Agent path traversalforgerock · web policy agents · CWE-23 | Kritik9,8 | — | %1,0 | 28 Şub 2023 |
39İzleyin | CVE-2023-0511İstismar yok | AM Java Policy Agent path traversalforgerock · java policy agents · CWE-23 | Kritik9,8 | — | %1,0 | 28 Şub 2023 |
39İzleyin | CVE-2022-3748İstismar yok | Improper authorization that can lead to account impersonationforgerock · access management · CWE-285 | Kritik9,8 | — | %0,9 | 14 Nis 2023 |
39İzleyin | CVE-2023-0582İstismar yok | Path Traversal in ForgeRock Access Managmentforgerock · access management · CWE-22 | Kritik9,8 | — | %0,8 | 27 Mar 2024 |
39İzleyin | CVE-2022-0143İstismar yok | LDAP Connector: When startTLS is used then LDAP connector ignores the wrong passwordforgerock · ldap connector · CWE-284 | Kritik9,8 | — | %0,6 | 19 Eyl 2022 |
33İzleyin | CVE-2016-6500İstismar yok | Unspecified methods in the RACF Connector component before 1.1.1.0 in ForgeRock OpenIDM and OpenICF improperly call the SearchControls constforgerock · racf connector · CWE-20 | Yüksek8,1 | — | %2,3 | 3 Şub 2017 |
32İzleyin | CVE-2019-3800İstismar yok | CF CLI writes the client id and secret to config filepivotal · cloud foundry command line interface · CWE-522 | Yüksek7,8 | — | %2,1 | 5 Ağu 2019 |
31İzleyin | CVE-2016-10097İstismar yok | XML External Entity (XXE) Vulnerability in /SSOPOST/metaAlias/%realm%/idpv2 in OpenAM - Access Management 10.1.0 allows remote attackers to forgerock · openam · CWE-611 | Yüksek7,5 | — | %2,5 | 2 Oca 2017 |
30İzleyin | CVE-2023-1656İstismar yok | When the LDAP connector is started with StartTLS configured, LDAP BIND credentials are transmitted insecurely, prior to establishing the TLS connection.forgerock · ldap connector · CWE-319 | Yüksek7,5 | — | %0,3 | 29 Mar 2023 |
26İzleyin | CVE-2018-7272İstismar yok | The REST APIs in ForgeRock AM before 5.5.0 include SSOToken IDs as part of the URL, which allows attackers to obtain sensitive information bforgerock · access management · CWE-200 | Orta6,5 | — | %0,9 | 20 Şub 2018 |
26İzleyin | CVE-2022-24670İstismar yok | Any user can run unrestricted LDAP queries against a configuration endpointforgerock · access management · CWE-200 | Orta6,5 | — | %0,6 | 27 Eki 2022 |
26İzleyin | CVE-2022-24669İstismar yok | Anonymous users can register / de-register for configuration change notificationsforgerock · access management · CWE-862 | Orta6,5 | — | %0,4 | 27 Eki 2022 |
24İzleyin | CVE-2017-14394İstismar yok | OAuth 2.0 Authorization Server of ForgeRock Access Management (OpenAM) 13.5.0-13.5.1 and Access Management (AM) 5.0.0-5.1.1 does not correctforgerock · access management · CWE-601 | Orta6,1 | — | %0,8 | 19 Haz 2019 |
24İzleyin | CVE-2017-14395İstismar yok | Auth 2.0 Authorization Server of ForgeRock Access Management (OpenAM) 13.5.0-13.5.1 and Access Management (AM) 5.0.0-5.1.1 does not correctlforgerock · access management · CWE-79 | Orta6,1 | — | %0,8 | 19 Haz 2019 |
24İzleyin | CVE-2020-17465İstismar yok | Dashboards and progressiveProfileForms in ForgeRock Identity Manager before 7.0.0 are vulnerable to stored XSS.forgerock · identity manager · CWE-79 | Orta6,1 | — | %0,7 | 31 Ağu 2020 |
20İzleyin | CVE-2024-25566İstismar yok | Open Redirect in PingAMforgerock · access management · CWE-601 | Orta5,1 | — | %0,2 | 29 Eki 2024 |
14İzleyin | CVE-2014-7246İstismar yok | The Core Server in OpenAM 9.5.3 through 9.5.5, 10.0.0 through 10.0.2, 10.1.0-Xpress, and 11.0.0 through 11.0.2, when deployed on a multi-serforgerock · openam · CWE-20 | Düşük3,5 | — | %1,1 | 13 Kas 2014 |
- CVE-2021-3546499Hemen
ForgeRock AM server before 7.0 has a Java deserialization vulnerability in the jato.pageSession parameter on multiple pages.
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100forgerock · access management22 Tem 2021
- CVE-2021-2915653Planlayın
ForgeRock OpenAM before 13.5.1 allows LDAP injection via the Webfinger protocol.
YüksekCVSS 7,5Kavram kanıtıEPSS %77forgerock · openam25 Mar 2021
- CVE-2021-420140Planlayın
Pre-authentication session hijacking
KritikCVSS 9,8İstismar yokEPSS %2forgerock · access management14 Şub 2022
- CVE-2021-3715439İzleyin
In ForgeRock Access Management (AM) before 7.0.2, the SAML2 implementation allows XML injection, potentially enabling a fraudulent SAML 2.0
KritikCVSS 9,8İstismar yokEPSS %1forgerock · access management25 Ağu 2021
- CVE-2021-3715339İzleyin
ForgeRock Access Management (AM) before 7.0.2, when configured with Active Directory as the Identity Store, has an authentication-bypass iss
KritikCVSS 9,8İstismar yokEPSS %1forgerock · access management25 Ağu 2021
- CVE-2023-033939İzleyin
AM Web Policy Agent path traversal
KritikCVSS 9,8İstismar yokEPSS %1forgerock · web policy agents28 Şub 2023
- CVE-2023-051139İzleyin
AM Java Policy Agent path traversal
KritikCVSS 9,8İstismar yokEPSS %1forgerock · java policy agents28 Şub 2023
- CVE-2022-374839İzleyin
Improper authorization that can lead to account impersonation
KritikCVSS 9,8İstismar yokEPSS %1forgerock · access management14 Nis 2023
- CVE-2023-058239İzleyin
Path Traversal in ForgeRock Access Managment
KritikCVSS 9,8İstismar yokEPSS %1forgerock · access management27 Mar 2024
- CVE-2022-014339İzleyin
LDAP Connector: When startTLS is used then LDAP connector ignores the wrong password
KritikCVSS 9,8İstismar yokEPSS %1forgerock · ldap connector19 Eyl 2022
- CVE-2016-650033İzleyin
Unspecified methods in the RACF Connector component before 1.1.1.0 in ForgeRock OpenIDM and OpenICF improperly call the SearchControls const
YüksekCVSS 8,1İstismar yokEPSS %2forgerock · racf connector3 Şub 2017
- CVE-2019-380032İzleyin
CF CLI writes the client id and secret to config file
YüksekCVSS 7,8İstismar yokEPSS %2pivotal · cloud foundry command line interface5 Ağu 2019
- CVE-2016-1009731İzleyin
XML External Entity (XXE) Vulnerability in /SSOPOST/metaAlias/%realm%/idpv2 in OpenAM - Access Management 10.1.0 allows remote attackers to
YüksekCVSS 7,5İstismar yokEPSS %2forgerock · openam2 Oca 2017
- CVE-2023-165630İzleyin
When the LDAP connector is started with StartTLS configured, LDAP BIND credentials are transmitted insecurely, prior to establishing the TLS connection.
YüksekCVSS 7,5İstismar yokEPSS %0forgerock · ldap connector29 Mar 2023
- CVE-2018-727226İzleyin
The REST APIs in ForgeRock AM before 5.5.0 include SSOToken IDs as part of the URL, which allows attackers to obtain sensitive information b
OrtaCVSS 6,5İstismar yokEPSS %1forgerock · access management20 Şub 2018
- CVE-2022-2467026İzleyin
Any user can run unrestricted LDAP queries against a configuration endpoint
OrtaCVSS 6,5İstismar yokEPSS %1forgerock · access management27 Eki 2022
- CVE-2022-2466926İzleyin
Anonymous users can register / de-register for configuration change notifications
OrtaCVSS 6,5İstismar yokEPSS %0forgerock · access management27 Eki 2022
- CVE-2017-1439424İzleyin
OAuth 2.0 Authorization Server of ForgeRock Access Management (OpenAM) 13.5.0-13.5.1 and Access Management (AM) 5.0.0-5.1.1 does not correct
OrtaCVSS 6,1İstismar yokEPSS %1forgerock · access management19 Haz 2019
- CVE-2017-1439524İzleyin
Auth 2.0 Authorization Server of ForgeRock Access Management (OpenAM) 13.5.0-13.5.1 and Access Management (AM) 5.0.0-5.1.1 does not correctl
OrtaCVSS 6,1İstismar yokEPSS %1forgerock · access management19 Haz 2019
- CVE-2020-1746524İzleyin
Dashboards and progressiveProfileForms in ForgeRock Identity Manager before 7.0.0 are vulnerable to stored XSS.
OrtaCVSS 6,1İstismar yokEPSS %1forgerock · identity manager31 Ağu 2020
- CVE-2024-2556620İzleyin
Open Redirect in PingAM
OrtaCVSS 5,1İstismar yokEPSS %0forgerock · access management29 Eki 2024
- CVE-2014-724614İzleyin
The Core Server in OpenAM 9.5.3 through 9.5.5, 10.0.0 through 10.0.2, 10.1.0-Xpress, and 11.0.0 through 11.0.2, when deployed on a multi-ser
DüşükCVSS 3,5İstismar yokEPSS %1forgerock · openam13 Kas 2014