{"cvss":9.8,"datePublished":"2021-11-03","dateUpdated":"2021-11-03","description":"ForgeRock Access Management (AM) Core Server allows an attacker who sends a specially crafted HTTP request to one of three endpoints (/ccversion/Version, /ccversion/Masthead, or /ccversion/ButtonFrame) to execute code in the context of the current user (unless ForgeRock AM is running as root user, which the vendor does not recommend).","dueDate":"2021-11-17","id":"CVE-2021-35464","kev_catalogs":["cisa"],"knownRansomwareCampaignUse":"Known","notes":"https://nvd.nist.gov/vuln/detail/CVE-2021-35464","product":"Access Management (AM)","requiredAction":"Apply updates per vendor instructions.","severity":"CRITICAL","source":"cisa_known_exploited","title":"ForgeRock Access Management (AM) Core Server Remote Code Execution Vulnerability","vendor":"ForgeRock"}