PatchSiren

ForgeRock CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

Known exploited ForgeRock CVE published 2021-11-03

CVE-2021-35464

CVE-2021-35464 is a remote code execution vulnerability affecting ForgeRock Access Management (AM) Core Server. It was added to CISA’s Known Exploited Vulnerabilities catalog on 2021-11-03, with CISA marking it for prompt remediation and noting known ransomware campaign use in the source metadata.