Description
Missing access control in ForgeRock Access Management 7.1.0 and earlier versions on all platforms allows remote unauthenticated attackers to hijack sessions, including potentially admin-level sessions. This issue affects: ForgeRock Access Management 7.1 versions prior to 7.1.1; 6.5 versions prior to 6.5.4; all previous versions.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Solution
This issue is fixed in AM 6.5.4, 7.1.1, and all later versions.
Vendor Workaround
Block access to the following endpoints: /authservice /sessionservice /profileservice /policyservice /namingservice /loggingservice
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-34059 | Missing access control in ForgeRock Access Management 7.1.0 and earlier versions on all platforms allows remote unauthenticated attackers to hijack sessions, including potentially admin-level sessions. This issue affects: ForgeRock Access Management 7.1 versions prior to 7.1.1; 6.5 versions prior to 6.5.4; all previous versions. |
References
History
No history.
Status: PUBLISHED
Assigner: ForgeRock
Published:
Updated: 2025-04-14T17:03:52.274Z
Reserved: 2022-01-06T00:00:00.000Z
Link: CVE-2021-4201
No data.
Status : Modified
Published: 2022-02-14T22:15:07.830
Modified: 2024-11-21T06:37:08.123
Link: CVE-2021-4201
No data.
OpenCVE Enrichment
No data.
EUVD