Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Forgerock

First CVE: Nov 14, 2014Active for: 12 yearsTotal CVEs: 22
56.3
VTI Score
TOP TARGET

Forgerock develops identity and access management platforms—including its Access Management and Identity Manager product lines—that sit at the authentication and authorization layer of enterprise infrastructure, where they mediate trust decisions for sensitive applications and data. The vendor's vulnerability footprint, though concentrated in a narrow product set, acquires disproportionate importance because identity and access control flaws can grant attackers broad privileges across downstream protected systems. Vulnerabilities affecting Forgerock skew strongly toward critical severity and display a moderate tendency toward public exploit availability, reflecting the high-value nature of identity platforms and the attack surface presented by authentication logic, LDAP connectors, and policy-enforcement agents. The recurring weakness classes—including sensitive information exposure, path traversal, improper access control, input validation defects, and cross-site scripting—are characteristic of web-facing authentication systems where validation and state management failures compound identity risks. Defenders should prioritize Forgerock advisories for rapid assessment and patching, particularly for internet-exposed instances, as exploitation of identity infrastructure can yield cascading compromise; live exploitation activity and severity counts are shown alongside this summary.

FAUCET AI Generated
22
Total CVEs
More Total CVEs than 96% of tracked vendors
0.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 3% of tracked vendors
7.9
Avg CVSS Score
Higher Avg CVSS Score than 77% of tracked vendors
4.5%
In CISA KEV
Higher KEV Rate than 99% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Forgerock over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 14, 2014
11 years ago
Most Recent CVE
Oct 29, 2024
633 days ago

Products(8 total)

Top CVEs

Signals from CVEs in this vendor scope (22 CVEs).

22 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2021-35464CRITICAL
ForgeRock AM server before 7.0 has a Java deserialization vulnerability in the jato.pageSession parameter on multiple pages. The exploitation does not require authentication, and r
Jul 22, 20219.899YESYES
CVE-2021-29156HIGH
ForgeRock OpenAM before 13.5.1 allows LDAP injection via the Webfinger protocol. For example, an unauthenticated attacker can perform character-by-character retrieval of password h
Mar 25, 20217.581NOYES
CVE-2022-3748CRITICAL
Improper Authorization vulnerability in ForgeRock Inc. Access Management allows Authentication Bypass. This issue affects Access Management: from 6.5.0 through 7.2.0.
Apr 14, 20239.831NONO
CVE-2021-4201CRITICAL
Missing access control in ForgeRock Access Management 7.1.0 and earlier versions on all platforms allows remote unauthenticated attackers to hijack sessions, including potentially
Feb 14, 20229.831NONO
CVE-2023-0511CRITICAL
Relative Path Traversal vulnerability in ForgeRock Access Management Java Policy Agent allows Authentication Bypass. This issue affects Access Management Java Policy Agent: all ver
Feb 28, 20239.830NONO
CVE-2021-37154CRITICAL
In ForgeRock Access Management (AM) before 7.0.2, the SAML2 implementation allows XML injection, potentially enabling a fraudulent SAML 2.0 assertion.
Aug 25, 20219.830NONO
CVE-2021-37153CRITICAL
ForgeRock Access Management (AM) before 7.0.2, when configured with Active Directory as the Identity Store, has an authentication-bypass issue.
Aug 25, 20219.830NONO
CVE-2023-0582CRITICAL
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ForgeRock Access Management allows Authorization Bypass. This issue affects access
Mar 27, 20249.829NONO
CVE-2023-0339CRITICAL
Relative Path Traversal vulnerability in ForgeRock Access Management Web Policy Agent allows Authentication Bypass. This issue affects Access Management Web Policy Agent: all versi
Feb 28, 20239.829NONO
CVE-2019-3800HIGH
CF CLI version prior to v6.45.0 (bosh release version 1.16.0) writes the client id and secret to its config file when the user authenticates with --client-credentials flag. A local
Aug 5, 20197.826NONO
View all 22 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products22 CVEs
32%
23%
41%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local1 (4.5%)
Network20 (90.9%)
Unknown1 (4.5%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low20 (90.9%)
High1 (4.5%)
Unknown1 (4.5%)
User Interaction
None17 (77.3%)
Unknown1 (4.5%)
Required4 (18.2%)
Privileges Required
Low3 (13.6%)
High0 (0.0%)
None18 (81.8%)
Unknown1 (4.5%)

Exploit Exposure

Signals from CVEs in this vendor scope (22 CVEs).

CISA KEV
1 CVE
4.5% of CVEs· 99th percentile
Metasploit
1 CVE
4.5% of CVEs· 98th percentile
Nuclei
2 CVEs
9.1% of CVEs· 96th percentile
ExploitDB
2 CVEs
9.1% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Forgerock.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Forgerock — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Forgerock's Products

View all 6 CNAs →

Top CWEs