Vulnerability Description
ForgeRock AM server before 7.0 has a Java deserialization vulnerability in the jato.pageSession parameter on multiple pages. The exploitation does not require authentication, and remote code execution can be triggered by sending a single crafted /ccversion/* request to the server. The vulnerability exists due to the usage of Sun ONE Application Framework (JATO) found in versions of Java 8 or earlier
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Forgerock | Access Management | < 6.5.4 |
| Forgerock | Openam | >= 9.0.0, < 14.6.3 |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/163486/ForgeRock-OpenAM-Jato-Java-DeserialiExploitThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/163525/ForgeRock-Access-Manager-OpenAM-14.6ExploitThird Party AdvisoryVDB Entry
- https://backstage.forgerock.com/knowledge/kb/article/a47894244ExploitPermissions RequiredVendor Advisory
- https://bugster.forgerock.orgBroken Link
- http://packetstormsecurity.com/files/163486/ForgeRock-OpenAM-Jato-Java-DeserialiExploitThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/163525/ForgeRock-Access-Manager-OpenAM-14.6ExploitThird Party AdvisoryVDB Entry
- https://backstage.forgerock.com/knowledge/kb/article/a47894244ExploitPermissions RequiredVendor Advisory
- https://bugster.forgerock.orgBroken Link
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-US Government Resource
FAQ
What is CVE-2021-35464?
CVE-2021-35464 is a vulnerability with a CVSS score of 9.8 (CRITICAL). ForgeRock AM server before 7.0 has a Java deserialization vulnerability in the jato.pageSession parameter on multiple pages. The exploitation does not require authentication, and remote code execution...
How severe is CVE-2021-35464?
CVE-2021-35464 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2021-35464?
Check the references section above for vendor advisories and patch information. Affected products include: Forgerock Access Management, Forgerock Openam.