Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

Pre-auth RCE in ForgeRock OpenAM (CVE-2021-35464)

Summary

A pre-auth RCE in ForgeRock OpenAM via unsafe deserialization in its Jato framework: the jato.pageSession parameter accepted Java objects exploitable with a custom ysoserial chain (CVE-2021-35464).
Published
Collected

original ↗

Related coverage

back