Description
ForgeRock AM / OpenAM uses Jato framework internally. The framework is vulnerable to java deserialization attacks. An attacker could exploit this vulnerability using specially-crafted serialized data to execute arbitrary code on the system.
Remediation
Upgrade to the latest version of ForgeRock AM
References
Related Vulnerabilities
WordPress Plugin Product Table by WBW Remote Code Execution (2.0.1)
WordPress 'wp-admin/options.php' Remote Code Execution Vulnerability (0.6.2 - 2.3.2)
Sonicwall SMA 100 Unintended proxy (CVE-2021-20042)
WordPress 2.1.1 Command Execution Backdoor Vulnerability (2.1.1)
WordPress Plugin open-flash-chart-core Remote Code Execution (0.4)