Blog | G5 Cyber Security

Critical RCE Flaw in ForgeRock Access Manager Under Active Attack

The vulnerability affects ForgeRock’s OpenAM access management tool. It could be leveraged to execute arbitrary code on an affected system remotely. The issue is a pre-authentication remote code execution (RCE) vulnerability in ForgeRock Access Manager. It stems from an unsafe Java deserialization in the Jato framework used by the software. ForgeRock customers are advised to move quickly to deploy the patches to mitigate the risk associated with the flaw. It has been addressed in version AM 7 released on June 29, 2021.

Source: https://thehackernews.com/2021/07/critical-rce-flaw-in-forgerock-access.html

Exit mobile version