ForgeRock AM server before 7.0 has a Java deserialization vulnerability in the jato.pageSession parameter on multiple pages. The exploitation does not require authentication, and remote code execution can be triggered by sending a single crafted /ccversion/* request to the server. The vulnerability exists due to the usage of Sun ONE Application Framework (JATO) found in versions of Java 8 or earlier
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HForgerock Access Management
APPForgerock< 6.5.4Forgerock Openam
APPForgerock9.0.0 – 14.6.3 (excl.)
CISA KEV — detailsi
- Vendori
- ForgeRock
- Producti
- Access Management (AM)
- Added to KEVi
- November 3, 2021
- Remediation deadline (US Federal)i
- November 17, 2021(overdue)
- Ransomwarei
- Active ransomware campaigns exploit this vulnerability
Apply updates per vendor instructions.
ForgeRock Access Management (AM) Core Server allows an attacker who sends a specially crafted HTTP request to one of three endpoints (/ccversion/Version, /ccversion/Masthead, or /ccversion/ButtonFrame) to execute code in the context of the current user (unless ForgeRock AM is running as root user, which the vendor does not recommend).
Related vulnerabilities
ForgeRock Access Management – Authentication Bypass poprzez niewłaściwą autoryzację
Pominięcie kontroli dostępu w ForgeRock Access Management — przejęcie sesji
XML Injection w ForgeRock Access Management — fałszywy assertion SAML 2.0
Pominięcie uwierzytelniania w ForgeRock Access Management z Active Directory
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ForgeRock Acce...