Umbra Wiki cve cve/CVE-2021-35464
Back to wiki

CVE-2021-35464 — ForgeRock Access Management (AM) Core Server Remote Code Execution Vulnerability

provenance: imported · CVE: CVE-2021-35464

CVE-2021-35464: ForgeRock Access Management (AM) Core Server Remote Code Execution Vulnerability

CISA Known Exploited Vulnerability (KEV)

Vendor / project ForgeRock
Product Access Management (AM)
Date added 2021-11-03
Due date 2021-11-17
Ransomware campaign use Known

Description

ForgeRock Access Management (AM) Core Server allows an attacker who sends a specially crafted HTTP request to one of three endpoints (/ccversion/Version, /ccversion/Masthead, or /ccversion/ButtonFrame) to execute code in the context of the current user (unless ForgeRock AM is running as root user, which the vendor does not recommend).

Required action (CISA)

Apply updates per vendor instructions.

Notes

https://nvd.nist.gov/vuln/detail/CVE-2021-35464

References

  • NVD: https://nvd.nist.gov/vuln/detail/CVE-2021-35464
  • KEV catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog