Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-63v3-hpf5-wfmw

Опубликовано: 15 фев. 2022
Источник: github
Github: Не прошло ревью

Описание

Missing access control in ForgeRock Access Management 7.1.0 and earlier versions on all platforms allows remote unauthenticated attackers to hijack sessions, including potentially admin-level sessions. This issue affects: ForgeRock Access Management 7.1 versions prior to 7.1.1; 6.5 versions prior to 6.5.4; all previous versions.

Missing access control in ForgeRock Access Management 7.1.0 and earlier versions on all platforms allows remote unauthenticated attackers to hijack sessions, including potentially admin-level sessions. This issue affects: ForgeRock Access Management 7.1 versions prior to 7.1.1; 6.5 versions prior to 6.5.4; all previous versions.

EPSS

Процентиль: 75%
0.00913
Низкий

Дефекты

CWE-287

Связанные уязвимости

CVSS3: 9.6
nvd
почти 4 года назад

Missing access control in ForgeRock Access Management 7.1.0 and earlier versions on all platforms allows remote unauthenticated attackers to hijack sessions, including potentially admin-level sessions. This issue affects: ForgeRock Access Management 7.1 versions prior to 7.1.1; 6.5 versions prior to 6.5.4; all previous versions.

EPSS

Процентиль: 75%
0.00913
Низкий

Дефекты

CWE-287