Junglewise Threat Intelligence

CVE-2021-35464: ForgeRock Access Management (AM) Core Server Remote Code Execution Vulnerability

CVE-2021-35464 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2021-11-03

Executive brief

ForgeRock Access Management (AM) server contains a Java deserialization vulnerability in the Sun ONE Application Framework (JATO) via the jato.pageSession parameter. An unauthenticated remote attacker can execute arbitrary code by sending a specially crafted HTTP request to endpoints such as /ccversion/Version, /ccversion/Masthead, or /ccversion/ButtonFrame.

Affected products

  • ForgeRock Access Management (AM) Core Server before 7.0
  • ForgeRock OpenAM 9.0.0 to 14.6.3

Timeline

  • 2021-08-02: disclosed: Initial NVD analysis and CVSS assignment
  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2021-11-03: other: Advisory published date