PT-2019-7969 · Forgerock · Access Management+1

Published

2019-06-19

·

Updated

2019-06-21

·

CVE-2017-14394

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions ForgeRock Access Management (OpenAM) versions 13.5.0 through 13.5.1 Access Management (AM) versions 5.0.0 through 5.1.1
Description The OAuth 2.0 Authorization Server does not correctly validate the redirect uri for some invalid requests, allowing attackers to perform phishing via an unvalidated redirect.
Recommendations For ForgeRock Access Management (OpenAM) versions 13.5.0 through 13.5.1, update the software to a version that correctly validates the redirect uri. For Access Management (AM) versions 5.0.0 through 5.1.1, update the software to a version that correctly validates the redirect uri. As a temporary workaround, consider restricting the use of the OAuth 2.0 Authorization Server until a patch is available.

Fix

Open Redirect

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-14394

Affected Products

Access Management
Forgerock Access Management