CVE-2017-14395: XSS
Auth 2.0 Authorization Server of ForgeRock Access Management (OpenAM) 13.5.0-13.5.1 and Access Management (AM) 5.0.0-5.1.1 does not correctly validate redirecturi for some invalid requests, which allows attackers to execute a script in the user's browser via reflected XSS.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2017-14395?
CVE-2017-14395 is a vulnerability in the Auth 2.0 Authorization Server of ForgeRock Access Management (OpenAM) 13.5.0-13.5.1 and Access Management (AM) 5.0.0-5.1.1.
What is the severity of CVE-2017-14395?
CVE-2017-14395 has a severity level of 6.1 (medium).
How does CVE-2017-14395 affect ForgeRock Access Management and OpenAM?
CVE-2017-14395 affects ForgeRock Access Management versions 5.0.0-5.1.1 and OpenAM versions 13.5.0-13.5.1.
What is the impact of CVE-2017-14395?
CVE-2017-14395 allows attackers to execute a script in the user's browser via reflected XSS (Cross-Site Scripting).
How can I fix CVE-2017-14395?
To fix CVE-2017-14395, it is recommended to upgrade ForgeRock Access Management to versions 5.1.2 or later, and OpenAM to versions 13.5.2 or later.