First published: Wed Aug 25 2021(Updated: )
In ForgeRock Access Management (AM) before 7.0.2, the SAML2 implementation allows XML injection, potentially enabling a fraudulent SAML 2.0 assertion.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ForgeRock Access Management | <7.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-37154 is a vulnerability in ForgeRock Access Management (AM) before version 7.0.2 that allows XML injection and potentially enables a fraudulent SAML 2.0 assertion.
The severity of CVE-2021-37154 is critical with a CVSSv3 score of 9.8.
CVE-2021-37154 affects ForgeRock Access Management (AM) versions prior to 7.0.2.
CVE-2021-37154 allows XML injection, potentially enabling a fraudulent SAML 2.0 assertion.
To fix CVE-2021-37154, you should update ForgeRock Access Management (AM) to version 7.0.2 or later.