CVE-2021-35464
ForgeRock AM server before 7.0 has a Java deserialization vulnerability in the jato.pageSession parameter on multiple pages. The exploitation does not require authentication, and remote code execution can be triggered by sending a single crafted /ccversion/* request to the server. The vulnerability exists due to the usage of Sun ONE Application Framework (JATO) found in versions of Java 8 or earlier
- Affected products
- Aws, Forgerock Access Management, Forgerock Openam, Java, Sun One Application Framework
- Forgerock Access Management
- < 6.5.4
- Forgerock Openam
- < 14.6.3
- Fix
- Available
- CVSS 2.0
- 10.0 HIGH
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 100.0% (100th percentile)
- Weakness
- CWE-502
- NVD status
- Analyzed
- Published
- 2021-07-22
CVE-2021-35464 at NVD
10 known exploits for CVE-2021-35464
Proof-of-concept code and exploit modules indexed by Sploitus
CVE-2026-33439
openam-CVE-2021-35464
CVE-2021-35464
ForgeRock Access Manager / OpenAM 14.6.3 - Remote Code Execution (Unauthenticated) Exploit
ForgeRock Access Manager 14.6.3 - Remote Code Execution (RCE) (Unauthenticated)
ForgeRock Access Manager/OpenAM 14.6.3 Remote Code Execution
ForgeRock / OpenAM Jato Java Deserialization
ForgeRock AM远程代码执行漏洞(CVE-2021-35464)
Exploit for Deserialization of Untrusted Data in Forgerock Access_Management
ForgeRock / OpenAM Jato Java Deserialization