VulnerabilityModified
CVE-2021-29156
ForgeRock OpenAM before 13.5.1 allows LDAP injection via the Webfinger protocol.
HIGH 7.5EPSS 76.4%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 76.4%, higher than 100% of all known CVEs. Patch or mitigate before the next change window.
Description
ForgeRock OpenAM before 13.5.1 allows LDAP injection via the Webfinger protocol. For example, an unauthenticated attacker can perform character-by-character retrieval of password hashes, or retrieve a session token or a private key.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 76.39% probability · 100th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-74
- Affected
- forgerock/openam
- Source
- cve@mitre.org
References
- https://bugster.forgerock.org/jira/browse/OPENAM-10135Exploit, Patch, Vendor Advisory
- https://portswigger.net/research/hidden-oauth-attack-vectorsExploit, Third Party Advisory
- https://bugster.forgerock.org/jira/browse/OPENAM-10135Exploit, Patch, Vendor Advisory
- https://portswigger.net/research/hidden-oauth-attack-vectorsExploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.