Pre-auth RCE in ForgeRock OpenAM (CVE-2021-35464)
portswigger.net | vulnerability | CVE-2021-35464 | #bug-bounty | #rce | #deserialization | #java-security | #forgerock-openam | #cve-2021-35464 | #pre-auth-rce | #ysoserial
Summary
A pre-auth RCE in ForgeRock OpenAM via unsafe deserialization in its Jato framework: the jato.pageSession parameter accepted Java objects exploitable with a custom ysoserial chain (CVE-2021-35464).
- Published
- Collected
Skip to content