Where
-Infinity
0

ForgeRock OpenAMOpenAM allows use of arbitrary OIDC requested claims values in id_token and user_info

Risk 80
Severity
8.1
First published (updated )

ForgeRock OpenDJOpenDJ Denial of Service (Dos) using alias loop

Risk 33
Severity
8.7
EPSS
0.05%
First published (updated )

ForgeRock Access ManagementOpen Redirect in PingAM

Risk 38
Severity
6.1
First published (updated )

ForgeRock Access ManagementPath Traversal in ForgeRock Access Managment

Risk 86
Severity
9.8
First published (updated )

ForgeRock Access ManagementImproper authorization that can lead to account impersonation

Risk 86
Severity
9.8
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

ForgeRock LDAP ConnectorWhen the LDAP connector is started with StartTLS configured, LDAP BIND credentials are transmitted insecurely, prior to establishing the TLS connection.

Risk 43
Severity
7.5
First published (updated )

ForgeRock Java Policy AgentsAM Java Policy Agent path traversal

Risk 86
Severity
9.8
First published (updated )

ForgeRock Web Policy AgentsAM Web Policy Agent path traversal

Risk 86
Severity
9.8
First published (updated )

ForgeRock Access ManagementAnonymous users can register / de-register for configuration change notifications

Risk 40
Severity
6.5
First published (updated )

ForgeRock Access ManagementAny user can run unrestricted LDAP queries against a configuration endpoint

Risk 48
Severity
7.1
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

ForgeRock LDAP ConnectorLDAP Connector: When startTLS is used then LDAP connector ignores the wrong password

Risk 86
Severity
9.8
First published (updated )

ForgeRock Access ManagementPre-authentication session hijacking

Risk 86
Severity
9.8
First published (updated )

ForgeRock Access ManagementForgeRock Access Management (AM) before 7.0.2, when configured with Active Directory as the Identity…

Risk 86
Severity
9.8
First published (updated )

ForgeRock Access ManagementIn ForgeRock Access Management (AM) before 7.0.2, the SAML2 implementation allows XML injection, pot…

Risk 87
Severity
9.8
First published (updated )

ForgeRock AMForgeRock Access Management (AM) Core Server Remote Code Execution Vulnerability

Risk 100
Severity
9.8
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

ForgeRock OpenAMForgeRock OpenAM before 13.5.1 allows LDAP injection via the Webfinger protocol. For example, an una…

Risk 43
Severity
7.5
First published (updated )

ForgeRock Identity ManagerXSS

Risk 38
Severity
6.1
First published (updated )

Pivotal Application ServiceCF CLI writes the client id and secret to config file

Risk 69
Severity
7.8
First published (updated )

ForgeRock Access ManagementXSS

Risk 38
Severity
6.1
First published (updated )

ForgeRock Access ManagementOAuth 2.0 Authorization Server of ForgeRock Access Management (OpenAM) 13.5.0-13.5.1 and Access Mana…

Risk 38
Severity
6.1
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

ForgeRock Access ManagementInfoleak

Risk 38
Severity
6.5
First published (updated )

ForgeRock RACF ConnectorInput Validation

Risk 75
Severity
8.1
First published (updated )

ForgeRock OpenAMXEE

Risk 43
Severity
7.5
First published (updated )

ForgeRock OpenAMInput Validation

Risk 18
Severity
3.5
First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203