Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

ForgeRock — Vulnerabilities & Security Advisories 7

Browse all 7 CVE security advisories affecting ForgeRock. AI-powered Chinese analysis, POCs, and references for each vulnerability.

ForgeRock provides identity and access management solutions, serving as a core authentication platform for enterprises. Historically, its products have faced vulnerabilities including remote code execution, cross-site scripting, and privilege escalation, with seven CVEs currently recorded. The platform's security characteristics include its widespread use in critical infrastructure, making any vulnerabilities particularly impactful. While no major public security incidents have been widely documented, the consistent discovery of CVEs suggests ongoing challenges in maintaining secure implementations across its complex authentication and authorization frameworks.

CVE ID Title CVSS Severity Published
CVE-2023-0582 Path Traversal in ForgeRock Access Managment — access management CWE-22 8.1 High 2024-03-27
CVE-2023-0511 AM Java Policy Agent path traversal — Access Management Java Policy Agent CWE-23 9.1 Critical 2023-02-28
CVE-2023-0339 AM Web Policy Agent path traversal — Access Management Web Policy Agent CWE-23 9.1 Critical 2023-02-28
CVE-2022-24669 Anonymous users can register / de-register for configuration change notifications — Access Management CWE-862 6.5 Medium 2022-10-27
CVE-2022-24670 Any user can run unrestricted LDAP queries against a configuration endpoint — Access Management CWE-200 7.1 High 2022-10-27
CVE-2022-0143 LDAP Connector: When startTLS is used then LDAP connector ignores the wrong password — LDAP Connector CWE-284 9.3 Critical 2022-09-19
CVE-2021-4201 Pre-authentication session hijacking — Access Management CWE-284 9.6 Critical 2022-02-14

This page lists every published CVE security advisory associated with ForgeRock. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.