CVE-2021-35464
ForgeRock Access Management (AM) Core Server Remote Code Execution Vulnerability
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 17 November 2021). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
ForgeRock AM server before 7.0 has a Java deserialization vulnerability in the jato.pageSession parameter on multiple pages. The exploitation does not require authentication, and remote code execution can be triggered by sending a single crafted /ccversion/* request to the server. The vulnerability exists due to the usage of Sun ONE Application Framework (JATO) found in versions of Java 8 or earlier
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 100.00% probability · 100th percentile
- CISA KEV
- Listed 3 November 2021 · due 17 November 2021 · used in ransomware campaigns
- Weakness
- CWE-502
- Affected
- forgerock/access management · forgerock/openam
- Source
- cve@mitre.org
CISA notes
Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2021-35464
References
- http://packetstormsecurity.com/files/163486/ForgeRock-OpenAM-Jato-Java-Deserialization.htmlExploit, Third Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/163525/ForgeRock-Access-Manager-OpenAM-14.6.3-Remote-Code-Execution.htmlExploit, Third Party Advisory, VDB Entry
- https://backstage.forgerock.com/knowledge/kb/article/a47894244Exploit, Permissions Required, Vendor Advisory
- https://bugster.forgerock.orgBroken Link
- http://packetstormsecurity.com/files/163486/ForgeRock-OpenAM-Jato-Java-Deserialization.htmlExploit, Third Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/163525/ForgeRock-Access-Manager-OpenAM-14.6.3-Remote-Code-Execution.htmlExploit, Third Party Advisory, VDB Entry
- https://backstage.forgerock.com/knowledge/kb/article/a47894244Exploit, Permissions Required, Vendor Advisory
- https://bugster.forgerock.orgBroken Link
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-35464US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.