Vulnerability Description
An Open-Redirect vulnerability exists in PingAM where well-crafted requests may cause improper validation of redirect URLs. This could allow an attacker to redirect end-users to malicious sites under their control, simplifying phishing attacks
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Forgerock | Access Management | <= 7.0.2 |
Related Weaknesses (CWE)
References
- https://backstage.forgerock.com/downloads/browse/am/featuredProduct
- https://backstage.forgerock.com/knowledge/advisories/article/a63463303MitigationVendor Advisory
FAQ
What is CVE-2024-25566?
CVE-2024-25566 is a vulnerability with a CVSS score of 6.1 (MEDIUM). An Open-Redirect vulnerability exists in PingAM where well-crafted requests may cause improper validation of redirect URLs. This could allow an attacker to redirect end-users to malicious sites under ...
How severe is CVE-2024-25566?
CVE-2024-25566 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-25566?
Check the references section above for vendor advisories and patch information. Affected products include: Forgerock Access Management.