CVE-2021-35464 is a critical Java deserialization vulnerability affecting ForgeRock AM server versions prior to 7.0 and ForgeRock OpenAM. This flaw allows unauthenticated remote code execution (RCE) by sending a single crafted request to the server, leveraging the outdated JATO framework. With a CVSS score of 9.8 (Critical) and an EPSS score indicating extremely high exploitability, this vulnerability poses a severe risk, enabling full compromise of affected systems. It is actively exploited in the wild, including in known ransomware campaigns, with public exploit modules available for Metasploit and Nuclei, and significant community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 6.5.4CPE matchmatch criteria | cpe:2.3:a:forgerock:access_management:*:*:*:*:*:*:*:* | ||
>= 9.0.0, < 14.6.3CPE matchmatch criteria | cpe:2.3:a:forgerock:openam:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.