漏洞信息详情
ForgeRock AM 代码问题漏洞
漏洞简介
ForgeRock AM是一个开源的访问管理、权限控制平台,在大学、社会组织中存在广泛的应用。
ForgeRock AM存在代码问题漏洞,未经身份验证的攻击者可以通过构造特殊的请求远程执行任意代码,并接管运行ForgeRockAM的服务器。
漏洞公告
目前厂商已发布升级补丁以修复漏洞,补丁获取链接:
https://backstage.forgerock.com/knowledge/kb/article/a47894244
参考网址
来源:MISC
链接:https://packetstormsecurity.com/files/163525/ForgeRock-Access-Manager-OpenAM-14.6.3-Remote-Code-Execution.html
来源:CONFIRM
链接:https://backstage.forgerock.com/knowledge/kb/article/a47894244
来源:MISC
链接:https://bugster.forgerock.org
来源:MISC
链接:https://packetstormsecurity.com/files/163486/ForgeRock-OpenAM-Jato-Java-Deserialization.html
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/163525/ForgeRock-Access-Manager-OpenAM-14.6.3-Remote-Code-Execution.html
来源:www.exploit-db.com
链接:https://www.exploit-db.com/exploits/50131
来源:nvd.nist.gov
链接:https://nvd.nist.gov/vuln/detail/CVE-2021-35464
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/163486/ForgeRock-OpenAM-Jato-Java-Deserialization.html
来源:cxsecurity.com
链接:https://cxsecurity.com/issue/WLB-2021070099
受影响实体
暂无
补丁
暂无
还没有评论,来说两句吧...