🔙 목록으로 돌아가기

CVE-2021-35464: ForgeRock OpenAM <7.0 - Remote Code Execution

TitleForgeRock OpenAM <7.0 - Remote Code Execution
Authormadrobot
SeverityCritical
ImpactSuccessful exploitation of this vulnerability could allow an attacker to execute arbitrary code on the affected system.
RemediationUpgrade ForgeRock OpenAM to version 7.0 or later to mitigate this vulnerability.
CVSS Score9.8
EPSS Score0.94386
CVE IDCVE-2021-35464
CWE IDCWE-502
Shodan Queryhttp.title:"OpenAM"http.title:"openam"
Fofa Querytitle="openam"
Tags cve cve2021 packetstorm openam rce java kev forgerock vkev vuln

🔍 Vulnerability Description

ForgeRock AM server before 7.0 has a Java deserialization vulnerability in the jato.pageSession parameter on multiple pages. The exploitation does not require authentication, and remote code execution can be triggered by sending a single crafted /ccversion/* request to the server. The vulnerability exists due to the usage of Sun ONE Application Framework (JATO) found in versions of Java 8 or earlier.

🌐 HTTP Request

GET /openam/oauth2/..;/ccversion/Version HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Version/15.2 Safari/537.36
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2021/CVE-2021-35464.yaml

🦈 Packet Capture: ⬇️ Download cve-2021-35464.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A