EXPOSURES › CVE-2021-35464
CVE-2021-35464
CRITICAL ⌖ ON CISA KEV · EXPLOITEDForgeRock's Access Management server had a critical remote code execution vulnerability actively exploited by ransomware actors.
A crafted HTTP request to ForgeRock AM's version endpoints allowed arbitrary code execution, potentially granting attackers full control of affected systems. DIB organizations using ForgeRock AM must immediately patch and review access controls to prevent compromise and maintain CMMC compliance. Failure to address this vulnerability could lead to significant data loss and regulatory penalties.
Shame score — The vulnerability's exploitation by ransomware and the ease of code execution represent a significant failure in secure coding practices and vendor security posture.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
ForgeRock Access Management (AM) Core Server allows an attacker who sends a specially crafted HTTP request to one of three endpoints (/ccversion/Version, /ccversion/Masthead, or /ccversion/ButtonFrame) to execute code in the context of the current user (unless ForgeRock AM is running as root user, which the vendor does not recommend).