Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 6.1
CVE-2024-25566
An Open-Redirect vulnerability exists in PingAM where well-crafted requests may cause improper validation of redirect URLs. This could allow an attac…
Access Management
after 7.2.2
CRITICAL 9.8
CVE-2023-0582
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ForgeRock Access Management allows Authorization Bypa…
Access Management
7.1.4+
CRITICAL 9.8
CVE-2022-3748
Improper Authorization vulnerability in ForgeRock Inc. Access Management allows Authentication Bypass. This issue affects Access Management: from 6.5…
Access Management
after 7.2.0
HIGH 7.5
CVE-2023-1656
Cleartext Transmission of Sensitive Information vulnerability in ForgeRock Inc. OpenIDM and Java Remote Connector Server (RCS) LDAP Connector on Wind…
Ldap Connector
1.5.20.14+
CRITICAL 9.8
CVE-2023-0339
Relative Path Traversal vulnerability in ForgeRock Access Management Web Policy Agent allows Authentication Bypass. This issue affects Access Managem…
Web Policy Agents
after 5.10.1
CRITICAL 9.8
CVE-2023-0511
Relative Path Traversal vulnerability in ForgeRock Access Management Java Policy Agent allows Authentication Bypass. This issue affects Access Manage…
Java Policy Agents
after 5.10.1
MEDIUM 6.5
CVE-2022-24669
It may be possible to gain some details of the deployment through a well-crafted attack. This may allow that data to be used to probe internal networ…
Access Management
after 7.0.2
MEDIUM 6.5
CVE-2022-24670
An attacker can use the unrestricted LDAP queries to determine configuration entries
Access Management
after 7.0.2
CRITICAL 9.8
CVE-2022-0143
When the LDAP connector is started with StartTLS configured, unauthenticated access is granted. This issue affects: all versions of the LDAP connecto…
Ldap Connector
1.5.20.9+
CRITICAL 9.8
CVE-2021-4201
Missing access control in ForgeRock Access Management 7.1.0 and earlier versions on all platforms allows remote unauthenticated attackers to hijack s…
Access Management
Patch available
CRITICAL 9.8
CVE-2021-37154
In ForgeRock Access Management (AM) before 7.0.2, the SAML2 implementation allows XML injection, potentially enabling a fraudulent SAML 2.0 assertion.
Access Management
7.0.2+
CRITICAL 9.8
CVE-2021-37153
ForgeRock Access Management (AM) before 7.0.2, when configured with Active Directory as the Identity Store, has an authentication-bypass issue.
Access Management
7.0.2+
CRITICAL 9.8
CVE-2021-35464 KEVEPSS 100%
ForgeRock AM server before 7.0 has a Java deserialization vulnerability in the jato.pageSession parameter on multiple pages. The exploitation does no…
Access Management
6.5.4 / 14.6.3+
HIGH 7.5
CVE-2021-29156EPSS 76%
ForgeRock OpenAM before 13.5.1 allows LDAP injection via the Webfinger protocol. For example, an unauthenticated attacker can perform character-by-ch…
Openam
13.5.1+
MEDIUM 6.1
CVE-2020-17465
Dashboards and progressiveProfileForms in ForgeRock Identity Manager before 7.0.0 are vulnerable to stored XSS. The vulnerability affects versions 6.…
Identity Manager
Mitigation only
MEDIUM 6.1
CVE-2017-14394
OAuth 2.0 Authorization Server of ForgeRock Access Management (OpenAM) 13.5.0-13.5.1 and Access Management (AM) 5.0.0-5.1.1 does not correctly valida…
Access Management
after 13.5.1
MEDIUM 6.1
CVE-2017-14395
Auth 2.0 Authorization Server of ForgeRock Access Management (OpenAM) 13.5.0-13.5.1 and Access Management (AM) 5.0.0-5.1.1 does not correctly validat…
Access Management
after 13.5.1
MEDIUM 6.5
CVE-2018-7272
The REST APIs in ForgeRock AM before 5.5.0 include SSOToken IDs as part of the URL, which allows attackers to obtain sensitive information by finding…
Access Management
5.5.0+
HIGH 8.1
CVE-2016-6500
Unspecified methods in the RACF Connector component before 1.1.1.0 in ForgeRock OpenIDM and OpenICF improperly call the SearchControls constructor wi…
Racf Connector
after 1.1.0.0
HIGH 7.5
CVE-2016-10097
XML External Entity (XXE) Vulnerability in /SSOPOST/metaAlias/%realm%/idpv2 in OpenAM - Access Management 10.1.0 allows remote attackers to read arbi…
Openam
Mitigation only