Vulnerabilities > Forgerock

DATE CVE VULNERABILITY TITLE RISK
2024-10-29 CVE-2024-25566 Open Redirect vulnerability in Forgerock Access Management
An Open-Redirect vulnerability exists in PingAM where well-crafted requests may cause improper validation of redirect URLs.
network
low complexity
forgerock CWE-601
6.1
2023-04-14 CVE-2022-3748 Unspecified vulnerability in Forgerock Access Management
Improper Authorization vulnerability in ForgeRock Inc.
network
low complexity
forgerock
critical
9.8
2023-03-29 CVE-2023-1656 Cleartext Transmission of Sensitive Information vulnerability in Forgerock Ldap Connector
Cleartext Transmission of Sensitive Information vulnerability in ForgeRock Inc.
network
low complexity
forgerock CWE-319
7.5
2023-02-28 CVE-2023-0339 Path Traversal vulnerability in Forgerock web Policy Agents 5.10/5.10.1
Relative Path Traversal vulnerability in ForgeRock Access Management Web Policy Agent allows Authentication Bypass. This issue affects Access Management Web Policy Agent: all versions up to 5.10.1
network
low complexity
forgerock CWE-22
critical
9.8
2023-02-28 CVE-2023-0511 Path Traversal vulnerability in Forgerock Java Policy Agents 5.10.1
Relative Path Traversal vulnerability in ForgeRock Access Management Java Policy Agent allows Authentication Bypass. This issue affects Access Management Java Policy Agent: all versions up to 5.10.1
network
low complexity
forgerock CWE-22
critical
9.8
2022-10-27 CVE-2022-24669 Missing Authorization vulnerability in Forgerock Access Management
It may be possible to gain some details of the deployment through a well-crafted attack.
network
low complexity
forgerock CWE-862
6.5
2022-10-27 CVE-2022-24670 Unspecified vulnerability in Forgerock Access Management
An attacker can use the unrestricted LDAP queries to determine configuration entries
network
low complexity
forgerock
6.5
2022-09-19 CVE-2022-0143 Incorrect Authorization vulnerability in Forgerock Ldap Connector
When the LDAP connector is started with StartTLS configured, unauthenticated access is granted.
network
low complexity
forgerock CWE-863
critical
9.8
2022-02-14 CVE-2021-4201 Improper Authentication vulnerability in Forgerock Access Management
Missing access control in ForgeRock Access Management 7.1.0 and earlier versions on all platforms allows remote unauthenticated attackers to hijack sessions, including potentially admin-level sessions.
network
low complexity
forgerock CWE-287
critical
9.8
2021-08-25 CVE-2021-37153 Unspecified vulnerability in Forgerock Access Management
ForgeRock Access Management (AM) before 7.0.2, when configured with Active Directory as the Identity Store, has an authentication-bypass issue.
network
low complexity
forgerock
critical
9.8