CVE-2021-37154: Critical severity ForgeRock Access Management vulnerability
In ForgeRock Access Management (AM) before 7.0.2, the SAML2 implementation allows XML injection, potentially enabling a fraudulent SAML 2.0 assertion.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
ForgeRock Access Management (AM) SAML2 implementationto a version that resolves this vulnerability.Fixed in 7.0.2
Event History
Frequently Asked Questions
What is CVE-2021-37154?
CVE-2021-37154 is a vulnerability in ForgeRock Access Management (AM) before version 7.0.2 that allows XML injection and potentially enables a fraudulent SAML 2.0 assertion.
What is the severity of CVE-2021-37154?
The severity of CVE-2021-37154 is critical with a CVSSv3 score of 9.8.
How does CVE-2021-37154 affect ForgeRock Access Management (AM)?
CVE-2021-37154 affects ForgeRock Access Management (AM) versions prior to 7.0.2.
How does CVE-2021-37154 work?
CVE-2021-37154 allows XML injection, potentially enabling a fraudulent SAML 2.0 assertion.
How can I fix CVE-2021-37154?
To fix CVE-2021-37154, you should update ForgeRock Access Management (AM) to version 7.0.2 or later.