First published: Wed Aug 25 2021(Updated: )
ForgeRock Access Management (AM) before 7.0.2, when configured with Active Directory as the Identity Store, has an authentication-bypass issue.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ForgeRock Access Management | >=6.0.0<7.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-37153 is a vulnerability in ForgeRock Access Management (AM) before 7.0.2 that allows an attacker to bypass authentication when AM is configured with Active Directory as the Identity Store.
CVE-2021-37153 has a severity rating of 9.8, which is considered critical.
ForgeRock Access Management versions before 7.0.2, when configured with Active Directory as the Identity Store, are affected by CVE-2021-37153.
To fix CVE-2021-37153, upgrade ForgeRock Access Management to version 7.0.2 or later.
More information about CVE-2021-37153 can be found at the following URLs: [link1](https://backstage.forgerock.com/knowledge/kb/article/a55763454) and [link2](https://www.forgerock.com/platform/access-management).