CVE-2023-0511: AM Java Policy Agent path traversal
Published Feb 28, 2023
·Updated
Relative Path Traversal vulnerability in ForgeRock Access Management Java Policy Agent allows Authentication Bypass. This issue affects Access Management Java Policy Agent: all versions up to 5.10.1
Affected Software
1 affected component
ForgeRock Java Policy Agents<=5.10.1
Event History
Feb 28, 2023
CVE Published
via MITRE·04:26 PM
Data Sourced
via MITRE·04:26 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-0511.
2
What is the severity level of CVE-2023-0511?
The severity level of CVE-2023-0511 is critical (9.8).
3
Which versions of ForgeRock Access Management Java Policy Agent are affected?
All versions up to 5.10.1 of ForgeRock Access Management Java Policy Agent are affected.
4
What is the impact of the Relative Path Traversal vulnerability?
The vulnerability allows for Authentication Bypass.
5
How can I fix this vulnerability?
To fix this vulnerability, update ForgeRock Access Management Java Policy Agent to a version above 5.10.1.