PT-2021-5345 · Oracle+2 · Java+4
Published
2021-06-29
·
Updated
2026-04-12
·
CVE-2021-35464
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
ForgeRock Access Management (AM) Core Server versions prior to 7.0
ForgeRock OpenAM version 14.6.3 and earlier
Description
The issue is related to a Java deserialization vulnerability in the
jato.pageSession parameter on multiple pages. This vulnerability allows for remote code execution without requiring authentication, which can be triggered by sending a crafted /ccversion/* request to the server. The vulnerability exists due to the incorrect usage of Sun ONE Application Framework (JATO) found in versions of Java 8 or earlier. It has been reported that this vulnerability has been exploited in real-world incidents, including a campaign by a financially motivated attacker targeting telecommunication service providers and business process outsourcing firms. The attacker used various tactics, including social engineering, to gain initial access to corporate networks and then used the vulnerability to execute code and elevate privileges on AWS.Recommendations
For ForgeRock Access Management (AM) Core Server versions prior to 7.0, update to version 7.0 or later to resolve the issue.
For ForgeRock OpenAM version 14.6.3 and earlier, update to a version later than 14.6.3 to resolve the issue.
As a temporary workaround, consider restricting access to the vulnerable
jato.pageSession parameter to minimize the risk of exploitation.
Avoid using the jato.pageSession parameter in the affected API endpoint until the issue is resolved.Exploit
Fix
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Aws
Forgerock Access Management
Forgerock Openam
Java
Sun One Application Framework