Back to search
CVE-2021-35464
Published: Jul 22, 2021
Modified: Oct 21, 2025
PUBLISHED
Description
ForgeRock AM server before 7.0 has a Java deserialization vulnerability in the jato.pageSession parameter on multiple pages. The exploitation does not require authentication, and remote code execution can be triggered by sending a single crafted /ccversion/* request to the server. The vulnerability exists due to the usage of Sun ONE Application Framework (JATO) found in versions of Java 8 or earlier
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
https://bugster.forgerock.org
x_refsource_MISC
https://backstage.forgerock.com/knowledge/kb/article/a47894244
x_refsource_CONFIRM
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now