CVE-2021-35464: ForgeRock OpenAM <7.0 - Remote Code Execution

CVE-2021-35464: ForgeRock OpenAM <7.0 - Remote Code Execution-渗透云记 - 专注于网络安全与技术分享
CVE-2021-35464: ForgeRock OpenAM <7.0 - Remote Code Execution
此内容为付费阅读,请付费后查看
100积分
付费阅读

漏洞标题

CVE-2021-35464: ForgeRock openam <7.0 – Remote Code Execution

漏洞描述

ForgeRock AM server before 7.0 has a Java deserialization vulnerability in the jato.pageSession parameter on multiple pages.

The exploitation does not require authentication, and remote code execution can be triggered by sending a single crafted

/ccversion/* request to the server. The vulnerability exists due to the usage of Sun ONE Application Framework (JATO)

found in versions of Java 8 or earlier.

PoC代码

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享