CVE-2021-35464

CVE-2021-35464

ForgeRock AM server 6.x before 7, and OpenAM 14.6.3, has a Java deserialization vulnerability in the jato.pageSession parameter on multiple pages. The exploitation does not require authentication, and remote code execution can be triggered by sending a single crafted /ccversion/Version request to the server. The vulnerability exists due to incorrect usage of Sun ONE Application Framework (JATO).

Source: CVE-2021-35464

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다