Skip to content
COOEY

EXPOSURES › CVE-2021-35464

CVE-2021-35464

CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2021-35464 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 72/100 ransomwarerceexploited-in-wild

ForgeRock's Access Management server had a critical remote code execution vulnerability actively exploited by ransomware actors.

A crafted HTTP request to ForgeRock AM's version endpoints allowed arbitrary code execution, potentially granting attackers full control of affected systems. DIB organizations using ForgeRock AM must immediately patch and review access controls to prevent compromise and maintain CMMC compliance. Failure to address this vulnerability could lead to significant data loss and regulatory penalties.

Shame score — The vulnerability's exploitation by ransomware and the ease of code execution represent a significant failure in secure coding practices and vendor security posture.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

ForgeRock Access Management (AM) Core Server allows an attacker who sends a specially crafted HTTP request to one of three endpoints (/ccversion/Version, /ccversion/Masthead, or /ccversion/ButtonFrame) to execute code in the context of the current user (unless ForgeRock AM is running as root user, which the vendor does not recommend).

SENTIMENT · TRUSTED SOURCES
synthesis severe-fallout -0.70
cooey ↗ severe-fallout -0.70
"…"
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.