CVE-2021-35464
ForgeRock Access Management (AM) Core Server Remote Code Execution Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
6Exploited in Wild
YesDecision
Descriptions
ForgeRock AM server before 7.0 has a Java deserialization vulnerability in the jato.pageSession parameter on multiple pages. The exploitation does not require authentication, and remote code execution can be triggered by sending a single crafted /ccversion/* request to the server. The vulnerability exists due to the usage of Sun ONE Application Framework (JATO) found in versions of Java 8 or earlier
El servidor ForgeRock AM anterior a la versión 7.0 tiene una vulnerabilidad de deserialización de Java en el parámetro jato.pageSession en varias páginas. La explotación no requiere autenticación, y la ejecución remota de código se puede desencadenar mediante el envío de una única solicitud /ccversion/* manipulada al servidor. La vulnerabilidad existe debido al uso de Sun ONE Application Framework (JATO) que se encuentra en las versiones de Java 8 o anteriores
ForgeRock Access Management (AM) Core Server allows an attacker who sends a specially crafted HTTP request to one of three endpoints (/ccversion/Version, /ccversion/Masthead, or /ccversion/ButtonFrame) to execute code in the context of the current user (unless ForgeRock AM is running as root user, which the vendor does not recommend).
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-06-23 CVE Reserved
- 2021-07-13 CVE Published
- 2021-07-16 First Exploit
- 2021-11-03 Exploited in Wild
- 2021-11-17 KEV Due Date
- 2024-08-04 CVE Updated
- 2024-11-24 EPSS Updated
CWE
- CWE-502: Deserialization of Untrusted Data
CAPEC
References (8)
URL | Tag | Source |
---|---|---|
https://bugster.forgerock.org | Broken Link | |
https://portswigger.net/research/pre-auth-rce-in-forgerock-openam-cve-2021-35464 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Forgerock Search vendor "Forgerock" | Am Search vendor "Forgerock" for product "Am" | >= 5.0.0 < 6.5.3 Search vendor "Forgerock" for product "Am" and version " >= 5.0.0 < 6.5.3" | - |
Affected
| ||||||
Forgerock Search vendor "Forgerock" | Openam Search vendor "Forgerock" for product "Openam" | >= 9.0.0 < 14.6.3 Search vendor "Forgerock" for product "Openam" and version " >= 9.0.0 < 14.6.3" | - |
Affected
|