First published: Wed Jun 19 2019(Updated: )
OAuth 2.0 Authorization Server of ForgeRock Access Management (OpenAM) 13.5.0-13.5.1 and Access Management (AM) 5.0.0-5.1.1 does not correctly validate redirect_uri for some invalid requests, which allows attackers to perform phishing via an unvalidated redirect.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ForgeRock Access Management | >=5.0.0<=5.1.1 | |
ForgeRock OpenAM | >=13.5.0<=13.5.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2017-14394 is medium with a CVSS score of 6.1.
CVE-2017-14394 affects ForgeRock Access Management versions 5.0.0-5.1.1.
CVE-2017-14394 affects ForgeRock OpenAM versions 13.5.0-13.5.1.
CVE-2017-14394 is a vulnerability in the OAuth 2.0 Authorization Server of ForgeRock Access Management and OpenAM that allows attackers to perform phishing via an unvalidated redirect.
Yes, there is a fix available for CVE-2017-14394. It is recommended to update to the latest version of ForgeRock Access Management or OpenAM.