CVE Tools

Forgerock

2 CVEs tracked since 2014. Since Nov 2014, none of them reached CISA KEV.

Forgerock CVEs per month

Nov 2014 to Feb 2017. Point at a month, or focus the strip and use the arrow keys.
Forgerock CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2014-1110
2014-12null or fewer
2015-01null or fewer
2015-02null or fewer
2015-03null or fewer
2015-04null or fewer
2015-05null or fewer
2015-06null or fewer
2015-07null or fewer
2015-08null or fewer
2015-09null or fewer
2015-10null or fewer
2015-11null or fewer
2015-12null or fewer
2016-01null or fewer
2016-02null or fewer
2016-03null or fewer
2016-04null or fewer
2016-05null or fewer
2016-06null or fewer
2016-07null or fewer
2016-08null or fewer
2016-09null or fewer
2016-10null or fewer
2016-11null or fewer
2016-12null or fewer
2017-01null or fewer
2017-0210

Products

The products that kept showing up in Forgerock's monthly top three, with their CVEs summed over those months.

  1. Openam11 month
  2. Racf Connector11 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Forgerock.

  1. CVE-2024-25566Open Redirect in PingAM6.1
  2. CVE-2023-0582Path Traversal in ForgeRock Access Managment8.1
  3. CVE-2022-3748Improper authorization that can lead to account impersonation9.8
  4. CVE-2023-1656When the LDAP connector is started with StartTLS configured, LDAP BIND credentials are transmitted insecurely, prior to establishing the TLS connection.7.5
  5. CVE-2023-0511AM Java Policy Agent path traversal9.1
  6. CVE-2023-0339AM Web Policy Agent path traversal9.1
  7. CVE-2022-24669Anonymous users can register / de-register for configuration change notifications6.5
  8. CVE-2022-24670Any user can run unrestricted LDAP queries against a configuration endpoint7.1
  9. CVE-2022-0143LDAP Connector: When startTLS is used then LDAP connector ignores the wrong password9.3
  10. CVE-2021-4201Pre-authentication session hijacking9.6
  11. CVE-2021-37153ForgeRock Access Management (AM) before 7.0.2, when configured with Active Directory as the Identity Store, has an authentication-bypass issue.9.8
  12. CVE-2021-37154In ForgeRock Access Management (AM) before 7.0.2, the SAML2 implementation allows XML injection, potentially enabling a fraudulent SAML 2.0 assertion.9.8
  13. CVE-2021-35464ForgeRock AM server before 7.0 has a Java deserialization vulnerability in the jato.pageSession parameter on multiple pages. The exploitation does not require authentication, and remote code execut...9.8
  14. CVE-2021-29156ForgeRock OpenAM before 13.5.1 allows LDAP injection via the Webfinger protocol. For example, an unauthenticated attacker can perform character-by-character retrieval of password hashes, or retriev...7.5
  15. CVE-2020-17465Dashboards and progressiveProfileForms in ForgeRock Identity Manager before 7.0.0 are vulnerable to stored XSS. The vulnerability affects versions 6.5.0.4, 6.0.0.6.6.1

The record

Peak rank
#118 in Nov 2014
Busiest month shown
Nov 2014, 1 CVEs
Months with a KEV entry
0 since Nov 2014
Monthly snapshots
2 since 2014
Forgerock's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store