Vulnerability index

Browse CVEs

20 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.1 CVE-2024-25566 An Open-Redirect vulnerability exists in PingAM where well-crafted requests may cause improper validation of redirect URLs. This could allow an attac… Access Management after 7.2.2 Fix from $1,6002024-10-29 CRITICAL 9.8 CVE-2023-0582 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ForgeRock Access Management allows Authorization Bypa… Access Management 7.1.4+ Fix from $2,3002024-03-27 CRITICAL 9.8 CVE-2022-3748 Improper Authorization vulnerability in ForgeRock Inc. Access Management allows Authentication Bypass. This issue affects Access Management: from 6.5… Access Management after 7.2.0 Fix from $2,3002023-04-14 HIGH 7.5 CVE-2023-1656 Cleartext Transmission of Sensitive Information vulnerability in ForgeRock Inc. OpenIDM and Java Remote Connector Server (RCS) LDAP Connector on Wind… Ldap Connector 1.5.20.14+ Fix from $1,9502023-03-29 CRITICAL 9.8 CVE-2023-0339 Relative Path Traversal vulnerability in ForgeRock Access Management Web Policy Agent allows Authentication Bypass. This issue affects Access Managem… Web Policy Agents after 5.10.1 Fix from $2,3002023-02-28 CRITICAL 9.8 CVE-2023-0511 Relative Path Traversal vulnerability in ForgeRock Access Management Java Policy Agent allows Authentication Bypass. This issue affects Access Manage… Java Policy Agents after 5.10.1 Fix from $2,3002023-02-28 MEDIUM 6.5 CVE-2022-24669 It may be possible to gain some details of the deployment through a well-crafted attack. This may allow that data to be used to probe internal networ… Access Management after 7.0.2 Fix from $1,6002022-10-27 MEDIUM 6.5 CVE-2022-24670 An attacker can use the unrestricted LDAP queries to determine configuration entries Access Management after 7.0.2 Fix from $1,6002022-10-27 CRITICAL 9.8 CVE-2022-0143 When the LDAP connector is started with StartTLS configured, unauthenticated access is granted. This issue affects: all versions of the LDAP connecto… Ldap Connector 1.5.20.9+ Fix from $2,3002022-09-19 CRITICAL 9.8 CVE-2021-4201 Missing access control in ForgeRock Access Management 7.1.0 and earlier versions on all platforms allows remote unauthenticated attackers to hijack s… Access Management Patch available Fix from $2,3002022-02-14 CRITICAL 9.8 CVE-2021-37154 In ForgeRock Access Management (AM) before 7.0.2, the SAML2 implementation allows XML injection, potentially enabling a fraudulent SAML 2.0 assertion. Access Management 7.0.2+ Fix from $2,3002021-08-25 CRITICAL 9.8 CVE-2021-37153 ForgeRock Access Management (AM) before 7.0.2, when configured with Active Directory as the Identity Store, has an authentication-bypass issue. Access Management 7.0.2+ Fix from $2,3002021-08-25 CRITICAL 9.8 CVE-2021-35464 KEVEPSS 100% ForgeRock AM server before 7.0 has a Java deserialization vulnerability in the jato.pageSession parameter on multiple pages. The exploitation does no… Access Management 6.5.4 / 14.6.3+ Fix from $2,3002021-07-22 HIGH 7.5 CVE-2021-29156EPSS 76% ForgeRock OpenAM before 13.5.1 allows LDAP injection via the Webfinger protocol. For example, an unauthenticated attacker can perform character-by-ch… Openam 13.5.1+ Fix from $1,9502021-03-25 MEDIUM 6.1 CVE-2020-17465 Dashboards and progressiveProfileForms in ForgeRock Identity Manager before 7.0.0 are vulnerable to stored XSS. The vulnerability affects versions 6.… Identity Manager Mitigation only Fix from $1,6002020-08-31 MEDIUM 6.1 CVE-2017-14394 OAuth 2.0 Authorization Server of ForgeRock Access Management (OpenAM) 13.5.0-13.5.1 and Access Management (AM) 5.0.0-5.1.1 does not correctly valida… Access Management after 13.5.1 Fix from $1,6002019-06-19 MEDIUM 6.1 CVE-2017-14395 Auth 2.0 Authorization Server of ForgeRock Access Management (OpenAM) 13.5.0-13.5.1 and Access Management (AM) 5.0.0-5.1.1 does not correctly validat… Access Management after 13.5.1 Fix from $1,6002019-06-19 MEDIUM 6.5 CVE-2018-7272 The REST APIs in ForgeRock AM before 5.5.0 include SSOToken IDs as part of the URL, which allows attackers to obtain sensitive information by finding… Access Management 5.5.0+ Fix from $1,6002018-02-21 HIGH 8.1 CVE-2016-6500 Unspecified methods in the RACF Connector component before 1.1.1.0 in ForgeRock OpenIDM and OpenICF improperly call the SearchControls constructor wi… Racf Connector after 1.1.0.0 Fix from $1,9502017-02-03 HIGH 7.5 CVE-2016-10097 XML External Entity (XXE) Vulnerability in /SSOPOST/metaAlias/%realm%/idpv2 in OpenAM - Access Management 10.1.0 allows remote attackers to read arbi… Openam Mitigation only Fix from $1,9502017-01-02