First published: Fri Apr 14 2023(Updated: )
Improper Authorization vulnerability in ForgeRock Inc. Access Management allows Authentication Bypass. This issue affects Access Management: from 6.5.0 through 7.2.0.
Credit: psirt@forgerock.com
Affected Software | Affected Version | How to fix |
---|---|---|
ForgeRock Access Management | >=6.5.0<=7.2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-3748 is critical with a CVSS score of 9.8.
CVE-2022-3748 affects ForgeRock Access Management versions from 6.5.0 through 7.2.0.
To fix the CVE-2022-3748 vulnerability, it is recommended to update ForgeRock Access Management to a version beyond 7.2.0.
The Common Weakness Enumeration (CWE) ID associated with CVE-2022-3748 is CWE-285.
More information about CVE-2022-3748 can be found on the ForgeRock website at the following links: - [Download ForgeRock Access Management](https://backstage.forgerock.com/downloads/browse/am/all/productId:am) - [ForgeRock Knowledge Base - CVE-2022-3748](https://backstage.forgerock.com/knowledge/kb/article/a34332318) - [ForgeRock Knowledge Base - Authentication Bypass](https://backstage.forgerock.com/knowledge/kb/article/a92134872)