ForgeRock records
22 published records for vendor forgerock.
Researcher profile
- Entered KEV
- 1 · 4.5%
- Weaponized
- 1 · 4.5%
- Pre-auth RCE
- 2
- With a fix record
- 4.5%
- Median publish → KEV
- 104 days
Recurring classes
- CWE-601 URL Redirection to Untrusted Site ('Open Redirect')2
- CWE-23 Relative Path Traversal2
- CWE-284 Improper Access Control2
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
- CWE-20 Improper Input Validation2
The weakness classes this vendor ships most often: where to look.
CWEAll records
22 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
99Now | CVE-2021-35464Weaponized | ForgeRock AM server before 7.0 has a Java deserialization vulnerability in the jato.pageSession parameter on multiple pages.forgerock · access management · CWE-502 | Critical9.8 | KEV | 100.0% | Jul 22, 2021 |
53Plan | CVE-2021-29156Proof of concept | ForgeRock OpenAM before 13.5.1 allows LDAP injection via the Webfinger protocol.forgerock · openam · CWE-74 | High7.5 | — | 76.8% | Mar 25, 2021 |
40Plan | CVE-2021-4201No exploit | Pre-authentication session hijackingforgerock · access management · CWE-284 | Critical9.8 | — | 2.0% | Feb 14, 2022 |
39Monitor | CVE-2021-37154No exploit | In ForgeRock Access Management (AM) before 7.0.2, the SAML2 implementation allows XML injection, potentially enabling a fraudulent SAML 2.0 forgerock · access management · CWE-91 | Critical9.8 | — | 1.4% | Aug 25, 2021 |
39Monitor | CVE-2021-37153No exploit | ForgeRock Access Management (AM) before 7.0.2, when configured with Active Directory as the Identity Store, has an authentication-bypass issforgerock · access management | Critical9.8 | — | 1.2% | Aug 25, 2021 |
39Monitor | CVE-2023-0339No exploit | AM Web Policy Agent path traversalforgerock · web policy agents · CWE-23 | Critical9.8 | — | 1.0% | Feb 28, 2023 |
39Monitor | CVE-2023-0511No exploit | AM Java Policy Agent path traversalforgerock · java policy agents · CWE-23 | Critical9.8 | — | 1.0% | Feb 28, 2023 |
39Monitor | CVE-2022-3748No exploit | Improper authorization that can lead to account impersonationforgerock · access management · CWE-285 | Critical9.8 | — | 0.9% | Apr 14, 2023 |
39Monitor | CVE-2023-0582No exploit | Path Traversal in ForgeRock Access Managmentforgerock · access management · CWE-22 | Critical9.8 | — | 0.8% | Mar 27, 2024 |
39Monitor | CVE-2022-0143No exploit | LDAP Connector: When startTLS is used then LDAP connector ignores the wrong passwordforgerock · ldap connector · CWE-284 | Critical9.8 | — | 0.6% | Sep 19, 2022 |
33Monitor | CVE-2016-6500No exploit | Unspecified methods in the RACF Connector component before 1.1.1.0 in ForgeRock OpenIDM and OpenICF improperly call the SearchControls constforgerock · racf connector · CWE-20 | High8.1 | — | 2.3% | Feb 3, 2017 |
32Monitor | CVE-2019-3800No exploit | CF CLI writes the client id and secret to config filepivotal · cloud foundry command line interface · CWE-522 | High7.8 | — | 2.1% | Aug 5, 2019 |
31Monitor | CVE-2016-10097No exploit | XML External Entity (XXE) Vulnerability in /SSOPOST/metaAlias/%realm%/idpv2 in OpenAM - Access Management 10.1.0 allows remote attackers to forgerock · openam · CWE-611 | High7.5 | — | 2.5% | Jan 2, 2017 |
30Monitor | CVE-2023-1656No exploit | When the LDAP connector is started with StartTLS configured, LDAP BIND credentials are transmitted insecurely, prior to establishing the TLS connection.forgerock · ldap connector · CWE-319 | High7.5 | — | 0.3% | Mar 29, 2023 |
26Monitor | CVE-2018-7272No exploit | The REST APIs in ForgeRock AM before 5.5.0 include SSOToken IDs as part of the URL, which allows attackers to obtain sensitive information bforgerock · access management · CWE-200 | Medium6.5 | — | 0.9% | Feb 20, 2018 |
26Monitor | CVE-2022-24670No exploit | Any user can run unrestricted LDAP queries against a configuration endpointforgerock · access management · CWE-200 | Medium6.5 | — | 0.6% | Oct 27, 2022 |
26Monitor | CVE-2022-24669No exploit | Anonymous users can register / de-register for configuration change notificationsforgerock · access management · CWE-862 | Medium6.5 | — | 0.4% | Oct 27, 2022 |
24Monitor | CVE-2017-14394No exploit | OAuth 2.0 Authorization Server of ForgeRock Access Management (OpenAM) 13.5.0-13.5.1 and Access Management (AM) 5.0.0-5.1.1 does not correctforgerock · access management · CWE-601 | Medium6.1 | — | 0.8% | Jun 19, 2019 |
24Monitor | CVE-2017-14395No exploit | Auth 2.0 Authorization Server of ForgeRock Access Management (OpenAM) 13.5.0-13.5.1 and Access Management (AM) 5.0.0-5.1.1 does not correctlforgerock · access management · CWE-79 | Medium6.1 | — | 0.8% | Jun 19, 2019 |
24Monitor | CVE-2020-17465No exploit | Dashboards and progressiveProfileForms in ForgeRock Identity Manager before 7.0.0 are vulnerable to stored XSS.forgerock · identity manager · CWE-79 | Medium6.1 | — | 0.7% | Aug 31, 2020 |
20Monitor | CVE-2024-25566No exploit | Open Redirect in PingAMforgerock · access management · CWE-601 | Medium5.1 | — | 0.2% | Oct 29, 2024 |
14Monitor | CVE-2014-7246No exploit | The Core Server in OpenAM 9.5.3 through 9.5.5, 10.0.0 through 10.0.2, 10.1.0-Xpress, and 11.0.0 through 11.0.2, when deployed on a multi-serforgerock · openam · CWE-20 | Low3.5 | — | 1.1% | Nov 13, 2014 |
- CVE-2021-3546499Now
ForgeRock AM server before 7.0 has a Java deserialization vulnerability in the jato.pageSession parameter on multiple pages.
CriticalCVSS 9.8KEVWeaponizedEPSS 100%forgerock · access managementJul 22, 2021
- CVE-2021-2915653Plan
ForgeRock OpenAM before 13.5.1 allows LDAP injection via the Webfinger protocol.
HighCVSS 7.5Proof of conceptEPSS 77%forgerock · openamMar 25, 2021
- CVE-2021-420140Plan
Pre-authentication session hijacking
CriticalCVSS 9.8No exploitEPSS 2%forgerock · access managementFeb 14, 2022
- CVE-2021-3715439Monitor
In ForgeRock Access Management (AM) before 7.0.2, the SAML2 implementation allows XML injection, potentially enabling a fraudulent SAML 2.0
CriticalCVSS 9.8No exploitEPSS 1%forgerock · access managementAug 25, 2021
- CVE-2021-3715339Monitor
ForgeRock Access Management (AM) before 7.0.2, when configured with Active Directory as the Identity Store, has an authentication-bypass iss
CriticalCVSS 9.8No exploitEPSS 1%forgerock · access managementAug 25, 2021
- CVE-2023-033939Monitor
AM Web Policy Agent path traversal
CriticalCVSS 9.8No exploitEPSS 1%forgerock · web policy agentsFeb 28, 2023
- CVE-2023-051139Monitor
AM Java Policy Agent path traversal
CriticalCVSS 9.8No exploitEPSS 1%forgerock · java policy agentsFeb 28, 2023
- CVE-2022-374839Monitor
Improper authorization that can lead to account impersonation
CriticalCVSS 9.8No exploitEPSS 1%forgerock · access managementApr 14, 2023
- CVE-2023-058239Monitor
Path Traversal in ForgeRock Access Managment
CriticalCVSS 9.8No exploitEPSS 1%forgerock · access managementMar 27, 2024
- CVE-2022-014339Monitor
LDAP Connector: When startTLS is used then LDAP connector ignores the wrong password
CriticalCVSS 9.8No exploitEPSS 1%forgerock · ldap connectorSep 19, 2022
- CVE-2016-650033Monitor
Unspecified methods in the RACF Connector component before 1.1.1.0 in ForgeRock OpenIDM and OpenICF improperly call the SearchControls const
HighCVSS 8.1No exploitEPSS 2%forgerock · racf connectorFeb 3, 2017
- CVE-2019-380032Monitor
CF CLI writes the client id and secret to config file
HighCVSS 7.8No exploitEPSS 2%pivotal · cloud foundry command line interfaceAug 5, 2019
- CVE-2016-1009731Monitor
XML External Entity (XXE) Vulnerability in /SSOPOST/metaAlias/%realm%/idpv2 in OpenAM - Access Management 10.1.0 allows remote attackers to
HighCVSS 7.5No exploitEPSS 2%forgerock · openamJan 2, 2017
- CVE-2023-165630Monitor
When the LDAP connector is started with StartTLS configured, LDAP BIND credentials are transmitted insecurely, prior to establishing the TLS connection.
HighCVSS 7.5No exploitEPSS 0%forgerock · ldap connectorMar 29, 2023
- CVE-2018-727226Monitor
The REST APIs in ForgeRock AM before 5.5.0 include SSOToken IDs as part of the URL, which allows attackers to obtain sensitive information b
MediumCVSS 6.5No exploitEPSS 1%forgerock · access managementFeb 20, 2018
- CVE-2022-2467026Monitor
Any user can run unrestricted LDAP queries against a configuration endpoint
MediumCVSS 6.5No exploitEPSS 1%forgerock · access managementOct 27, 2022
- CVE-2022-2466926Monitor
Anonymous users can register / de-register for configuration change notifications
MediumCVSS 6.5No exploitEPSS 0%forgerock · access managementOct 27, 2022
- CVE-2017-1439424Monitor
OAuth 2.0 Authorization Server of ForgeRock Access Management (OpenAM) 13.5.0-13.5.1 and Access Management (AM) 5.0.0-5.1.1 does not correct
MediumCVSS 6.1No exploitEPSS 1%forgerock · access managementJun 19, 2019
- CVE-2017-1439524Monitor
Auth 2.0 Authorization Server of ForgeRock Access Management (OpenAM) 13.5.0-13.5.1 and Access Management (AM) 5.0.0-5.1.1 does not correctl
MediumCVSS 6.1No exploitEPSS 1%forgerock · access managementJun 19, 2019
- CVE-2020-1746524Monitor
Dashboards and progressiveProfileForms in ForgeRock Identity Manager before 7.0.0 are vulnerable to stored XSS.
MediumCVSS 6.1No exploitEPSS 1%forgerock · identity managerAug 31, 2020
- CVE-2024-2556620Monitor
Open Redirect in PingAM
MediumCVSS 5.1No exploitEPSS 0%forgerock · access managementOct 29, 2024
- CVE-2014-724614Monitor
The Core Server in OpenAM 9.5.3 through 9.5.5, 10.0.0 through 10.0.2, 10.1.0-Xpress, and 11.0.0 through 11.0.2, when deployed on a multi-ser
LowCVSS 3.5No exploitEPSS 1%forgerock · openamNov 13, 2014