PT-2019-7969 · Forgerock · Access Management+1
Publicado
2019-06-19
·
Atualizado
2019-06-21
·
CVE-2017-14394
CVSS v3.1
6.1
Média
| Vetor | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
ForgeRock Access Management (OpenAM) versions 13.5.0 through 13.5.1
Access Management (AM) versions 5.0.0 through 5.1.1
Description
The OAuth 2.0 Authorization Server does not correctly validate the
redirect uri for some invalid requests, allowing attackers to perform phishing via an unvalidated redirect.Recommendations
For ForgeRock Access Management (OpenAM) versions 13.5.0 through 13.5.1, update the software to a version that correctly validates the
redirect uri.
For Access Management (AM) versions 5.0.0 through 5.1.1, update the software to a version that correctly validates the redirect uri.
As a temporary workaround, consider restricting the use of the OAuth 2.0 Authorization Server until a patch is available.Correção
Open Redirect
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Access Management
Forgerock Access Management