CVE-2021-37153: Critical severity ForgeRock Access Management vulnerability
ForgeRock Access Management (AM) before 7.0.2, when configured with Active Directory as the Identity Store, has an authentication-bypass issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
ForgeRock Access Management (AM)to a version that resolves this vulnerability.Fixed in 7.0.2
Event History
Frequently Asked Questions
What is CVE-2021-37153?
CVE-2021-37153 is a vulnerability in ForgeRock Access Management (AM) before 7.0.2 that allows an attacker to bypass authentication when AM is configured with Active Directory as the Identity Store.
How severe is CVE-2021-37153?
CVE-2021-37153 has a severity rating of 9.8, which is considered critical.
What is affected by CVE-2021-37153?
ForgeRock Access Management versions before 7.0.2, when configured with Active Directory as the Identity Store, are affected by CVE-2021-37153.
How can I fix CVE-2021-37153?
To fix CVE-2021-37153, upgrade ForgeRock Access Management to version 7.0.2 or later.
Where can I find more information about CVE-2021-37153?
More information about CVE-2021-37153 can be found at the following URLs: [link1](https://backstage.forgerock.com/knowledge/kb/article/a55763454) and [link2](https://www.forgerock.com/platform/access-management).