First published: Wed Jun 19 2019(Updated: )
Auth 2.0 Authorization Server of ForgeRock Access Management (OpenAM) 13.5.0-13.5.1 and Access Management (AM) 5.0.0-5.1.1 does not correctly validate redirect_uri for some invalid requests, which allows attackers to execute a script in the user's browser via reflected XSS.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ForgeRock Access Management | >=5.0.0<=5.1.1 | |
ForgeRock OpenAM | >=13.5.0<=13.5.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-14395 is a vulnerability in the Auth 2.0 Authorization Server of ForgeRock Access Management (OpenAM) 13.5.0-13.5.1 and Access Management (AM) 5.0.0-5.1.1.
CVE-2017-14395 has a severity level of 6.1 (medium).
CVE-2017-14395 affects ForgeRock Access Management versions 5.0.0-5.1.1 and OpenAM versions 13.5.0-13.5.1.
CVE-2017-14395 allows attackers to execute a script in the user's browser via reflected XSS (Cross-Site Scripting).
To fix CVE-2017-14395, it is recommended to upgrade ForgeRock Access Management to versions 5.1.2 or later, and OpenAM to versions 13.5.2 or later.