Vulnerability index

Browse CVEs

20 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Access Management MEDIUM 6.1
CVE-2024-25566

An Open-Redirect vulnerability exists in PingAM where well-crafted requests may cause improper validation of redirect URLs. This could allow an attac…

Fix: after 7.2.2
Fix from $1,600 2024-10-29
Access Management CRITICAL 9.8
CVE-2023-0582

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ForgeRock Access Management allows Authorization Bypa…

Fix: 7.1.4+
Fix from $2,300 2024-03-27
Access Management CRITICAL 9.8
CVE-2022-3748

Improper Authorization vulnerability in ForgeRock Inc. Access Management allows Authentication Bypass. This issue affects Access Management: from 6.5…

Fix: after 7.2.0
Fix from $2,300 2023-04-14
Ldap Connector HIGH 7.5
CVE-2023-1656

Cleartext Transmission of Sensitive Information vulnerability in ForgeRock Inc. OpenIDM and Java Remote Connector Server (RCS) LDAP Connector on Wind…

Fix: 1.5.20.14+
Fix from $1,950 2023-03-29
Web Policy Agents CRITICAL 9.8
CVE-2023-0339

Relative Path Traversal vulnerability in ForgeRock Access Management Web Policy Agent allows Authentication Bypass. This issue affects Access Managem…

Fix: after 5.10.1
Fix from $2,300 2023-02-28
Java Policy Agents CRITICAL 9.8
CVE-2023-0511

Relative Path Traversal vulnerability in ForgeRock Access Management Java Policy Agent allows Authentication Bypass. This issue affects Access Manage…

Fix: after 5.10.1
Fix from $2,300 2023-02-28
Access Management MEDIUM 6.5
CVE-2022-24669

It may be possible to gain some details of the deployment through a well-crafted attack. This may allow that data to be used to probe internal networ…

Fix: after 7.0.2
Fix from $1,600 2022-10-27
Access Management MEDIUM 6.5
CVE-2022-24670

An attacker can use the unrestricted LDAP queries to determine configuration entries

Fix: after 7.0.2
Fix from $1,600 2022-10-27
Ldap Connector CRITICAL 9.8
CVE-2022-0143

When the LDAP connector is started with StartTLS configured, unauthenticated access is granted. This issue affects: all versions of the LDAP connecto…

Fix: 1.5.20.9+
Fix from $2,300 2022-09-19
Access Management CRITICAL 9.8
CVE-2021-4201

Missing access control in ForgeRock Access Management 7.1.0 and earlier versions on all platforms allows remote unauthenticated attackers to hijack s…

Patch available
Fix from $2,300 2022-02-14
Access Management CRITICAL 9.8
CVE-2021-37154

In ForgeRock Access Management (AM) before 7.0.2, the SAML2 implementation allows XML injection, potentially enabling a fraudulent SAML 2.0 assertion.

Fix: 7.0.2+
Fix from $2,300 2021-08-25
Access Management CRITICAL 9.8
CVE-2021-37153

ForgeRock Access Management (AM) before 7.0.2, when configured with Active Directory as the Identity Store, has an authentication-bypass issue.

Fix: 7.0.2+
Fix from $2,300 2021-08-25
Access Management CRITICAL 9.8
CVE-2021-35464 KEVEPSS 100%

ForgeRock AM server before 7.0 has a Java deserialization vulnerability in the jato.pageSession parameter on multiple pages. The exploitation does no…

Fix: 6.5.4 / 14.6.3+
Fix from $2,300 2021-07-22
Openam HIGH 7.5
CVE-2021-29156EPSS 76%

ForgeRock OpenAM before 13.5.1 allows LDAP injection via the Webfinger protocol. For example, an unauthenticated attacker can perform character-by-ch…

Fix: 13.5.1+
Fix from $1,950 2021-03-25
Identity Manager MEDIUM 6.1
CVE-2020-17465

Dashboards and progressiveProfileForms in ForgeRock Identity Manager before 7.0.0 are vulnerable to stored XSS. The vulnerability affects versions 6.…

Mitigation only
Fix from $1,600 2020-08-31
Access Management MEDIUM 6.1
CVE-2017-14394

OAuth 2.0 Authorization Server of ForgeRock Access Management (OpenAM) 13.5.0-13.5.1 and Access Management (AM) 5.0.0-5.1.1 does not correctly valida…

Fix: after 13.5.1
Fix from $1,600 2019-06-19
Access Management MEDIUM 6.1
CVE-2017-14395

Auth 2.0 Authorization Server of ForgeRock Access Management (OpenAM) 13.5.0-13.5.1 and Access Management (AM) 5.0.0-5.1.1 does not correctly validat…

Fix: after 13.5.1
Fix from $1,600 2019-06-19
Access Management MEDIUM 6.5
CVE-2018-7272

The REST APIs in ForgeRock AM before 5.5.0 include SSOToken IDs as part of the URL, which allows attackers to obtain sensitive information by finding…

Fix: 5.5.0+
Fix from $1,600 2018-02-21
Racf Connector HIGH 8.1
CVE-2016-6500

Unspecified methods in the RACF Connector component before 1.1.1.0 in ForgeRock OpenIDM and OpenICF improperly call the SearchControls constructor wi…

Fix: after 1.1.0.0
Fix from $1,950 2017-02-03
Openam HIGH 7.5
CVE-2016-10097

XML External Entity (XXE) Vulnerability in /SSOPOST/metaAlias/%realm%/idpv2 in OpenAM - Access Management 10.1.0 allows remote attackers to read arbi…

Mitigation only
Fix from $1,950 2017-01-02