CVE-2021-35464 Scanner
Detects 'Remote Code Execution (RCE)' vulnerability in ForgeRock AM Server affects v. before 7.0.
Used 2.8k times · 5.9k assets checked · url
ForgeRock AM server before 7.0 has a Java deserialization vulnerability in the jato.pageSession parameter on multiple pages. The exploitation does not require authentication, and remote code execution can be triggered by sending a single crafted /ccversion/* request to the server. The vulnerability exists due to the usage of Sun ONE Application Framework (JATO) found in versions of Java 8 or earlier
Detects 'Remote Code Execution (RCE)' vulnerability in ForgeRock AM Server affects v. before 7.0.
Used 2.8k times · 5.9k assets checked · url
S4E maps published CVEs to scanners and forecasts the next disclosure window for your stack.
Create a free account →