CVE-2021-4201: Pre-authentication session hijacking
Missing access control in ForgeRock Access Management 7.1.0 and earlier versions on all platforms allows remote unauthenticated attackers to hijack sessions, including potentially admin-level sessions. This issue affects: ForgeRock Access Management 7.1 versions prior to 7.1.1; 6.5 versions prior to 6.5.4; all previous versions.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2021-4201?
CVE-2021-4201 is a vulnerability in ForgeRock Access Management 7.1.0 and earlier versions on all platforms that allows remote unauthenticated attackers to hijack sessions, including potentially admin-level sessions.
What is the severity of CVE-2021-4201?
CVE-2021-4201 has a severity rating of 9.8, which is considered critical.
How does CVE-2021-4201 affect ForgeRock Access Management?
CVE-2021-4201 affects ForgeRock Access Management 7.1 versions prior to 7.1.1 and 6.5 versions prior to 6.5.3.
What are the affected versions of ForgeRock Access Management?
The affected versions of ForgeRock Access Management include 7.1.0, 7.0.2, 7.0.1, 7.0.0, 6.5.3, 6.5.2.3, 6.5.2.2, 6.5.2.1, 6.5.2, 6.5.1, 6.5.0.2, 6.5.0.1, 6.5.0, 6.0.0.7, 6.0.0.6, 6.0.0.4, 6.0.0.3, 6.0.0.2, 6.0.0.1, and 6.0.0.
Where can I find more information about CVE-2021-4201?
You can find more information about CVE-2021-4201 at the following link: [CVE-2021-4201](https://backstage.forgerock.com/knowledge/kb/article/a50037155#x7ZPA0)