Vulnerabilities (CVE)

Filtered by vendor Forgerock Subscribe
Filtered by product Access Management
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-37153 1 Forgerock 1 Access Management 2022-07-12 7.5 HIGH 9.8 CRITICAL
ForgeRock Access Management (AM) before 7.0.2, when configured with Active Directory as the Identity Store, has an authentication-bypass issue.
CVE-2021-4201 1 Forgerock 1 Access Management 2022-02-23 7.5 HIGH 9.8 CRITICAL
Missing access control in ForgeRock Access Management 7.1.0 and earlier versions on all platforms allows remote unauthenticated attackers to hijack sessions, including potentially admin-level sessions. This issue affects: ForgeRock Access Management 7.1 versions prior to 7.1.1; 6.5 versions prior to 6.5.4; all previous versions.
CVE-2021-37154 1 Forgerock 1 Access Management 2021-09-01 10.0 HIGH 9.8 CRITICAL
In ForgeRock Access Management (AM) before 7.0.2, the SAML2 implementation allows XML injection, potentially enabling a fraudulent SAML 2.0 assertion.