CVE-2021-29156: High severity openam vulnerability
Published Mar 25, 2021
·Updated
ForgeRock OpenAM before 13.5.1 allows LDAP injection via the Webfinger protocol. For example, an unauthenticated attacker can perform character-by-character retrieval of password hashes, or retrieve a session token or a private key.
Affected Software
1 affected component
ForgeRock OpenAM<13.5.1
Remediation
Patch Available
Event History
Mar 25, 2021
CVE Published
via MITRE·08:20 AM
Data Sourced
via MITRE·08:20 AM
Description
Frequently Asked Questions
1
What is CVE-2021-29156?
CVE-2021-29156 is a vulnerability in ForgeRock OpenAM versions before 13.5.1 that allows LDAP injection via the Webfinger protocol.
2
How does CVE-2021-29156 impact the system?
CVE-2021-29156 allows an unauthenticated attacker to perform character-by-character retrieval of password hashes, retrieve a session token, or a private key.
3
How severe is CVE-2021-29156?
CVE-2021-29156 has a severity rating of 7.5 (high).
4
How can I fix CVE-2021-29156?
To fix CVE-2021-29156, upgrade ForgeRock OpenAM to version 13.5.1 or later.
5
Are there any references for more information about CVE-2021-29156?
Yes, you can find more information about CVE-2021-29156 at the following references: [1] [2]