PT-2019-7969 · Forgerock · Access Management+1

Publicado

2019-06-19

·

Atualizado

2019-06-21

·

CVE-2017-14394

CVSS v3.1

6.1

Média

VetorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions ForgeRock Access Management (OpenAM) versions 13.5.0 through 13.5.1 Access Management (AM) versions 5.0.0 through 5.1.1
Description The OAuth 2.0 Authorization Server does not correctly validate the redirect uri for some invalid requests, allowing attackers to perform phishing via an unvalidated redirect.
Recommendations For ForgeRock Access Management (OpenAM) versions 13.5.0 through 13.5.1, update the software to a version that correctly validates the redirect uri. For Access Management (AM) versions 5.0.0 through 5.1.1, update the software to a version that correctly validates the redirect uri. As a temporary workaround, consider restricting the use of the OAuth 2.0 Authorization Server until a patch is available.

Correção

Open Redirect

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-14394

Produtos afetados

Access Management
Forgerock Access Management