CVE-2023-0339: AM Web Policy Agent path traversal
Published Feb 28, 2023
·Updated
Relative Path Traversal vulnerability in ForgeRock Access Management Web Policy Agent allows Authentication Bypass. This issue affects Access Management Web Policy Agent: all versions up to 5.10.1
Affected Software
1 affected component
ForgeRock Web Policy Agents<=5.10.1
Event History
Feb 28, 2023
CVE Published
via MITRE·04:21 PM
Data Sourced
via MITRE·04:21 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2023-0339.
2
What is the title of the vulnerability?
The title of the vulnerability is Relative Path Traversal vulnerability in ForgeRock Access Management Web Policy Agent allows Authentication Bypass.
3
Which versions of ForgeRock Access Management Web Policy Agent are affected?
All versions up to 5.10.1 of ForgeRock Access Management Web Policy Agent are affected.
4
What is the severity of the vulnerability?
The severity of the vulnerability is critical.
5
How can I fix the vulnerability?
To fix the vulnerability, update ForgeRock Access Management Web Policy Agent to version 5.10.1 or later.