CVE-2021-4201
Last modified
CVE-2021-4201 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. Missing access control in ForgeRock Access Management 7.1.0 and earlier versions on all platforms allows remote unauthenticated attackers to hijack sessions, including potentially admin-level sessions. This issue affects: ForgeRock Access Management 7.1 versions prior to 7.1.1; 6.5 versions prior to 6.5.4; all previous versions.. EPSS estimates a 1.95% chance of exploitation in the next 30 days.
Description
Missing access control in ForgeRock Access Management 7.1.0 and earlier versions on all platforms allows remote unauthenticated attackers to hijack sessions, including potentially admin-level sessions. This issue affects: ForgeRock Access Management 7.1 versions prior to 7.1.1; 6.5 versions prior to 6.5.4; all previous versions.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Forgerock | Access Management | 5.5.2 |
| Forgerock | Access Management | 6.0.0 |
| Forgerock | Access Management | 6.0.0.1 |
| Forgerock | Access Management | 6.0.0.2 |
| Forgerock | Access Management | 6.0.0.3 |
| Forgerock | Access Management | 6.0.0.4 |
| Forgerock | Access Management | 6.0.0.6 |
| Forgerock | Access Management | 6.0.0.7 |
| Forgerock | Access Management | 6.5.0 |
| Forgerock | Access Management | 6.5.0.1 |
| Forgerock | Access Management | 6.5.0.2 |
| Forgerock | Access Management | 6.5.1 |
| Forgerock | Access Management | 6.5.2.1 |
| Forgerock | Access Management | 6.5.2.2 |
| Forgerock | Access Management | 6.5.2.3 |
| Forgerock | Access Management | 6.5.3 |
| Forgerock | Access Management | 7.0.0 |
| Forgerock | Access Management | 7.0.1 |
| Forgerock | Access Management | 7.0.2 |
| Forgerock | Access Management | 7.1.0 |
References
- https://backstage.forgerock.com/knowledge/kb/article/a50037155#x7ZPA0Patch, Vendor Advisory
- https://backstage.forgerock.com/knowledge/kb/article/a50037155#x7ZPA0Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-4201?
How severe is CVE-2021-4201?
How do I fix CVE-2021-4201?
Are you affected by CVE-2021-4201?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
