Executive brief
ForgeRock Access Management (AM) server contains a Java deserialization vulnerability in the Sun ONE Application Framework (JATO) via the jato.pageSession parameter. An unauthenticated remote attacker can execute arbitrary code by sending a specially crafted HTTP request to endpoints such as /ccversion/Version, /ccversion/Masthead, or /ccversion/ButtonFrame.
Affected products
- ForgeRock Access Management (AM) Core Server before 7.0
- ForgeRock OpenAM 9.0.0 to 14.6.3
Timeline
- 2021-08-02: disclosed: Initial NVD analysis and CVSS assignment
- 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2021-11-03: other: Advisory published date