📦

access_management

Vendor: forgerock

Actively Exploited 1 CISA KEV List
PoC / Exploits 1 Code Available
Total RCEs 1 Remote Access
Total CVEs 13 Total Indexed
Avg. EPSS 9.15% Exploit Prob.
Latest CVE CVE-2024-25566 Oct 29

Security Vulnerability Index

Page 2 / 2
6.1 CVSS

OAuth 2.0 Authorization Server of ForgeRock Access Management (OpenAM) 13.5.0-13.5.1 and Access Management (AM) 5.0.0-5.1.1 does not correctly validate redirect_uri for some invalid requests, which allows attackers to perform phishing via an unvalidated redirect.

EPSS: 0.79%
6.5 CVSS

The REST APIs in ForgeRock AM before 5.5.0 include SSOToken IDs as part of the URL, which allows attackers to obtain sensitive information by finding an ID value in a log file.

EPSS: 0.88%