CVE-2017-14394: Medium severity forgerock access management (am) vulnerability
OAuth 2.0 Authorization Server of ForgeRock Access Management (OpenAM) 13.5.0-13.5.1 and Access Management (AM) 5.0.0-5.1.1 does not correctly validate redirecturi for some invalid requests, which allows attackers to perform phishing via an unvalidated redirect.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-14394?
The severity of CVE-2017-14394 is medium with a CVSS score of 6.1.
How does CVE-2017-14394 affect ForgeRock Access Management?
CVE-2017-14394 affects ForgeRock Access Management versions 5.0.0-5.1.1.
How does CVE-2017-14394 affect ForgeRock OpenAM?
CVE-2017-14394 affects ForgeRock OpenAM versions 13.5.0-13.5.1.
What is the vulnerability description of CVE-2017-14394?
CVE-2017-14394 is a vulnerability in the OAuth 2.0 Authorization Server of ForgeRock Access Management and OpenAM that allows attackers to perform phishing via an unvalidated redirect.
Is there a fix available for CVE-2017-14394?
Yes, there is a fix available for CVE-2017-14394. It is recommended to update to the latest version of ForgeRock Access Management or OpenAM.