Skip to content
Noroxi

ForgeRock records

22 published records for vendor forgerock.

All records

22 records
  • ForgeRock AM server before 7.0 has a Java deserialization vulnerability in the jato.pageSession parameter on multiple pages.

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    forgerock · access managementJul 22, 2021

  • ForgeRock OpenAM before 13.5.1 allows LDAP injection via the Webfinger protocol.

    HighCVSS 7.5Proof of conceptEPSS 77%

    forgerock · openamMar 25, 2021

  • Pre-authentication session hijacking

    CriticalCVSS 9.8No exploitEPSS 2%

    forgerock · access managementFeb 14, 2022

  • In ForgeRock Access Management (AM) before 7.0.2, the SAML2 implementation allows XML injection, potentially enabling a fraudulent SAML 2.0

    CriticalCVSS 9.8No exploitEPSS 1%

    forgerock · access managementAug 25, 2021

  • ForgeRock Access Management (AM) before 7.0.2, when configured with Active Directory as the Identity Store, has an authentication-bypass iss

    CriticalCVSS 9.8No exploitEPSS 1%

    forgerock · access managementAug 25, 2021

  • CVE-2023-0339
    39Monitor

    AM Web Policy Agent path traversal

    CriticalCVSS 9.8No exploitEPSS 1%

    forgerock · web policy agentsFeb 28, 2023

  • CVE-2023-0511
    39Monitor

    AM Java Policy Agent path traversal

    CriticalCVSS 9.8No exploitEPSS 1%

    forgerock · java policy agentsFeb 28, 2023

  • CVE-2022-3748
    39Monitor

    Improper authorization that can lead to account impersonation

    CriticalCVSS 9.8No exploitEPSS 1%

    forgerock · access managementApr 14, 2023

  • CVE-2023-0582
    39Monitor

    Path Traversal in ForgeRock Access Managment

    CriticalCVSS 9.8No exploitEPSS 1%

    forgerock · access managementMar 27, 2024

  • CVE-2022-0143
    39Monitor

    LDAP Connector: When startTLS is used then LDAP connector ignores the wrong password

    CriticalCVSS 9.8No exploitEPSS 1%

    forgerock · ldap connectorSep 19, 2022

  • CVE-2016-6500
    33Monitor

    Unspecified methods in the RACF Connector component before 1.1.1.0 in ForgeRock OpenIDM and OpenICF improperly call the SearchControls const

    HighCVSS 8.1No exploitEPSS 2%

    forgerock · racf connectorFeb 3, 2017

  • CVE-2019-3800
    32Monitor

    CF CLI writes the client id and secret to config file

    HighCVSS 7.8No exploitEPSS 2%

    pivotal · cloud foundry command line interfaceAug 5, 2019

  • XML External Entity (XXE) Vulnerability in /SSOPOST/metaAlias/%realm%/idpv2 in OpenAM - Access Management 10.1.0 allows remote attackers to

    HighCVSS 7.5No exploitEPSS 2%

    forgerock · openamJan 2, 2017

  • CVE-2023-1656
    30Monitor

    When the LDAP connector is started with StartTLS configured, LDAP BIND credentials are transmitted insecurely, prior to establishing the TLS connection.

    HighCVSS 7.5No exploitEPSS 0%

    forgerock · ldap connectorMar 29, 2023

  • CVE-2018-7272
    26Monitor

    The REST APIs in ForgeRock AM before 5.5.0 include SSOToken IDs as part of the URL, which allows attackers to obtain sensitive information b

    MediumCVSS 6.5No exploitEPSS 1%

    forgerock · access managementFeb 20, 2018

  • Any user can run unrestricted LDAP queries against a configuration endpoint

    MediumCVSS 6.5No exploitEPSS 1%

    forgerock · access managementOct 27, 2022

  • Anonymous users can register / de-register for configuration change notifications

    MediumCVSS 6.5No exploitEPSS 0%

    forgerock · access managementOct 27, 2022

  • OAuth 2.0 Authorization Server of ForgeRock Access Management (OpenAM) 13.5.0-13.5.1 and Access Management (AM) 5.0.0-5.1.1 does not correct

    MediumCVSS 6.1No exploitEPSS 1%

    forgerock · access managementJun 19, 2019

  • Auth 2.0 Authorization Server of ForgeRock Access Management (OpenAM) 13.5.0-13.5.1 and Access Management (AM) 5.0.0-5.1.1 does not correctl

    MediumCVSS 6.1No exploitEPSS 1%

    forgerock · access managementJun 19, 2019

  • Dashboards and progressiveProfileForms in ForgeRock Identity Manager before 7.0.0 are vulnerable to stored XSS.

    MediumCVSS 6.1No exploitEPSS 1%

    forgerock · identity managerAug 31, 2020

  • Open Redirect in PingAM

    MediumCVSS 5.1No exploitEPSS 0%

    forgerock · access managementOct 29, 2024

  • CVE-2014-7246
    14Monitor

    The Core Server in OpenAM 9.5.3 through 9.5.5, 10.0.0 through 10.0.2, 10.1.0-Xpress, and 11.0.0 through 11.0.2, when deployed on a multi-ser

    LowCVSS 3.5No exploitEPSS 1%

    forgerock · openamNov 13, 2014