Vulnerabilities > Forgerock > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2022-10-27 | CVE-2022-24669 | Missing Authorization vulnerability in Forgerock Access Management It may be possible to gain some details of the deployment through a well-crafted attack. | 6.5 |
2022-10-27 | CVE-2022-24670 | Unspecified vulnerability in Forgerock Access Management An attacker can use the unrestricted LDAP queries to determine configuration entries | 6.5 |
2021-03-25 | CVE-2021-29156 | Injection vulnerability in Forgerock Openam ForgeRock OpenAM before 13.5.1 allows LDAP injection via the Webfinger protocol. | 5.0 |
2020-08-31 | CVE-2020-17465 | Cross-site Scripting vulnerability in Forgerock Identity Manager 6.0.0.6/6.5.0.4 Dashboards and progressiveProfileForms in ForgeRock Identity Manager before 7.0.0 are vulnerable to stored XSS. | 4.3 |
2019-06-19 | CVE-2017-14395 | Cross-site Scripting vulnerability in Forgerock Access Management and Openam Auth 2.0 Authorization Server of ForgeRock Access Management (OpenAM) 13.5.0-13.5.1 and Access Management (AM) 5.0.0-5.1.1 does not correctly validate redirect_uri for some invalid requests, which allows attackers to execute a script in the user's browser via reflected XSS. | 4.3 |
2019-06-19 | CVE-2017-14394 | Open Redirect vulnerability in Forgerock Access Management and Openam OAuth 2.0 Authorization Server of ForgeRock Access Management (OpenAM) 13.5.0-13.5.1 and Access Management (AM) 5.0.0-5.1.1 does not correctly validate redirect_uri for some invalid requests, which allows attackers to perform phishing via an unvalidated redirect. | 5.8 |
2018-02-21 | CVE-2018-7272 | Information Exposure vulnerability in Forgerock Access Management 5.0.0/5.1.0/5.1.1 The REST APIs in ForgeRock AM before 5.5.0 include SSOToken IDs as part of the URL, which allows attackers to obtain sensitive information by finding an ID value in a log file. | 4.0 |
2017-02-03 | CVE-2016-6500 | Improper Input Validation vulnerability in Forgerock Racf Connector Unspecified methods in the RACF Connector component before 1.1.1.0 in ForgeRock OpenIDM and OpenICF improperly call the SearchControls constructor with returnObjFlag set to true, which allows remote attackers to execute arbitrary code via a crafted serialized Java object, aka LDAP entry poisoning. | 6.8 |
2017-01-02 | CVE-2016-10097 | XXE vulnerability in Forgerock Openam 10.1.0 XML External Entity (XXE) Vulnerability in /SSOPOST/metaAlias/%realm%/idpv2 in OpenAM - Access Management 10.1.0 allows remote attackers to read arbitrary files via the SAMLRequest parameter. | 5.0 |