CVE-2022-3748: Improper authorization that can lead to account impersonation
Improper Authorization vulnerability in ForgeRock Inc. Access Management allows Authentication Bypass. This issue affects Access Management: from 6.5.0 through 7.2.0.
Other sources
Improper Authorization vulnerability in ForgeRock Inc. Access Management allows Authentication Bypass.This issue affects Access Management: from 6.5.0 through 7.2.0.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-3748?
The severity of CVE-2022-3748 is critical with a CVSS score of 9.8.
Which versions of ForgeRock Access Management are affected by CVE-2022-3748?
CVE-2022-3748 affects ForgeRock Access Management versions from 6.5.0 through 7.2.0.
How can I fix the CVE-2022-3748 vulnerability?
To fix the CVE-2022-3748 vulnerability, it is recommended to update ForgeRock Access Management to a version beyond 7.2.0.
What is the Common Weakness Enumeration (CWE) ID associated with CVE-2022-3748?
The Common Weakness Enumeration (CWE) ID associated with CVE-2022-3748 is CWE-285.
Where can I find more information about CVE-2022-3748?
More information about CVE-2022-3748 can be found on the ForgeRock website at the following links: - [Download ForgeRock Access Management](https://backstage.forgerock.com/downloads/browse/am/all/productId:am) - [ForgeRock Knowledge Base - CVE-2022-3748](https://backstage.forgerock.com/knowledge/kb/article/a34332318) - [ForgeRock Knowledge Base - Authentication Bypass](https://backstage.forgerock.com/knowledge/kb/article/a92134872)