Forgerock develops identity and access management platforms—including its Access Management and Identity Manager product lines—that sit at the authentication and authorization layer of enterprise infrastructure, where they mediate trust decisions for sensitive applications and data. The vendor's vulnerability footprint, though concentrated in a narrow product set, acquires disproportionate importance because identity and access control flaws can grant attackers broad privileges across downstream protected systems. Vulnerabilities affecting Forgerock skew strongly toward critical severity and display a moderate tendency toward public exploit availability, reflecting the high-value nature of identity platforms and the attack surface presented by authentication logic, LDAP connectors, and policy-enforcement agents. The recurring weakness classes—including sensitive information exposure, path traversal, improper access control, input validation defects, and cross-site scripting—are characteristic of web-facing authentication systems where validation and state management failures compound identity risks. Defenders should prioritize Forgerock advisories for rapid assessment and patching, particularly for internet-exposed instances, as exploitation of identity infrastructure can yield cascading compromise; live exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Forgerock over time
Signals from CVEs in this vendor scope (22 CVEs).
22 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-35464CRITICAL ForgeRock AM server before 7.0 has a Java deserialization vulnerability in the jato.pageSession parameter on multiple pages. The exploitation does not require authentication, and r | Jul 22, 2021 | 9.8 | 99 | YES | YES |
CVE-2021-29156HIGH ForgeRock OpenAM before 13.5.1 allows LDAP injection via the Webfinger protocol. For example, an unauthenticated attacker can perform character-by-character retrieval of password h | Mar 25, 2021 | 7.5 | 81 | NO | YES |
CVE-2022-3748CRITICAL Improper Authorization vulnerability in ForgeRock Inc. Access Management allows Authentication Bypass. This issue affects Access Management: from 6.5.0 through 7.2.0. | Apr 14, 2023 | 9.8 | 31 | NO | NO |
CVE-2021-4201CRITICAL Missing access control in ForgeRock Access Management 7.1.0 and earlier versions on all platforms allows remote unauthenticated attackers to hijack sessions, including potentially | Feb 14, 2022 | 9.8 | 31 | NO | NO |
CVE-2023-0511CRITICAL Relative Path Traversal vulnerability in ForgeRock Access Management Java Policy Agent allows Authentication Bypass. This issue affects Access Management Java Policy Agent: all ver | Feb 28, 2023 | 9.8 | 30 | NO | NO |
CVE-2021-37154CRITICAL In ForgeRock Access Management (AM) before 7.0.2, the SAML2 implementation allows XML injection, potentially enabling a fraudulent SAML 2.0 assertion. | Aug 25, 2021 | 9.8 | 30 | NO | NO |
CVE-2021-37153CRITICAL ForgeRock Access Management (AM) before 7.0.2, when configured with Active Directory as the Identity Store, has an authentication-bypass issue. | Aug 25, 2021 | 9.8 | 30 | NO | NO |
CVE-2023-0582CRITICAL Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ForgeRock Access Management allows Authorization Bypass.
This issue affects access | Mar 27, 2024 | 9.8 | 29 | NO | NO |
CVE-2023-0339CRITICAL Relative Path Traversal vulnerability in ForgeRock Access Management Web Policy Agent allows Authentication Bypass. This issue affects Access Management Web Policy Agent: all versi | Feb 28, 2023 | 9.8 | 29 | NO | NO |
CVE-2019-3800HIGH CF CLI version prior to v6.45.0 (bosh release version 1.16.0) writes the client id and secret to its config file when the user authenticates with --client-credentials flag. A local | Aug 5, 2019 | 7.8 | 26 | NO | NO |
Signals from CVEs in this vendor scope (22 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Forgerock.
Media articles that mention a CVE ID that affects a product developed by Forgerock — matched by CVE ID, not by vendor name.