← Vulnerability feed

Vulnerability record · CVE-2017-14395 · published 19 June 2019

CVE-2017-14395: Forgerock access management cross-site scripting vulnerability

Forgerock · Access Management

Auth 2.0 Authorization Server of ForgeRock Access Management (OpenAM) 13.5.0-13.5.1 and Access Management (AM) 5.0.0-5.1.1 does not correctly validate redirect_uri for some invalid requests, which allows attackers to execute a script in the user's browser via reflected XSS.

6.1 CVSS 3.0 Medium EPSS 0.79% · top 45.4% CWE-79 · Cross-site scripting
6.1CVSS 3.0 base score, v2 4.3
0.79%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Auth 2.0 Authorization Server of ForgeRock Access Management (OpenAM) 13.5.0-13.5.1 and Access Management (AM) 5.0.0-5.1.1 does not correctly validate redirect_uri for some invalid requests, which allows attackers to execute a script in the user's browser via reflected XSS.

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2017-14395 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-35464ForgeRock AM JATO deserialization remote code executionForgeRock Access Management (AM) server before 7.0 deserializes untrusted data from the jato.pageSession parameter on multiple pages, a flaw inherite…KEVEPSS 100%analysed9.8CVE-2023-0582Forgerock access management path traversal vulnerabilityImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ForgeRock Access Management allows Authorization Bypa…EPSS 0.78%9.8CVE-2022-3748Forgerock access management improper authorization vulnerabilityImproper Authorization vulnerability in ForgeRock Inc. Access Management allows Authentication Bypass. This issue affects Access Management: from 6.5…EPSS 0.91%9.8CVE-2021-4201Forgerock access management improper access control vulnerabilityMissing access control in ForgeRock Access Management 7.1.0 and earlier versions on all platforms allows remote unauthenticated attackers to hijack s…EPSS 2.0%9.8CVE-2021-37154Forgerock access management xml injection vulnerabilityIn ForgeRock Access Management (AM) before 7.0.2, the SAML2 implementation allows XML injection, potentially enabling a fraudulent SAML 2.0 assertion.EPSS 1.4%9.8CVE-2021-37153Forgerock access management vulnerabilityForgeRock Access Management (AM) before 7.0.2, when configured with Active Directory as the Identity Store, has an authentication-bypass issue.EPSS 1.2%7.5CVE-2021-29156ForgeRock OpenAM LDAP injection via WebfingerForgeRock OpenAM before 13.5.1 is vulnerable to LDAP injection through the Webfinger protocol. An unauthenticated attacker can inject LDAP filter con…EPSS 77%analysed7.5CVE-2016-10097Forgerock openam xml external entity (xxe) vulnerabilityXML External Entity (XXE) Vulnerability in /SSOPOST/metaAlias/%realm%/idpv2 in OpenAM - Access Management 10.1.0 allows remote attackers to read arbi…EPSS 2.5%

Source: NIST National Vulnerability Database (record CVE-2017-14395), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.