Looking for the vulnerability index of Invicti's legacy products?
ForgeRock AM / OpenAM Deserialization RCE (CVE-2021-35464) - Vulnerability Database

ForgeRock AM / OpenAM Deserialization RCE (CVE-2021-35464)

Description

ForgeRock AM / OpenAM uses Jato framework internally. The framework is vulnerable to java deserialization attacks. An attacker could exploit this vulnerability using specially-crafted serialized data to execute arbitrary code on the system.

Remediation

Upgrade to the latest version of ForgeRock AM

Related Vulnerabilities