← Vulnerability feed

Vulnerability record · CVE-2021-29156 · published 25 March 2021

CVE-2021-29156: ForgeRock OpenAM LDAP injection via Webfinger

Forgerock · Openam

ForgeRock OpenAM before 13.5.1 is vulnerable to LDAP injection through the Webfinger protocol. An unauthenticated attacker can inject LDAP filter content to extract sensitive data such as password hashes, session tokens, or private keys. This is a high-severity information disclosure flaw in an identity and access management product.

7.5 CVSS 3.1 High EPSS 77% · top 0.5% CWE-74 · Injection
7.5CVSS 3.1 base score, v2 5.0
77%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

ForgeRock OpenAM before 13.5.1 allows LDAP injection via the Webfinger protocol. For example, an unauthenticated attacker can perform character-by-character retrieval of password hashes, or retrieve a session token or a private key.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

high priorityUnauthenticated network-accessible LDAP injection with high confidentiality impact and very high EPSS, though not in KEV.

What it is

ForgeRock OpenAM before 13.5.1 is vulnerable to LDAP injection through the Webfinger protocol. An unauthenticated attacker can inject LDAP filter content to extract sensitive data such as password hashes, session tokens, or private keys. This is a high-severity information disclosure flaw in an identity and access management product.

Impact

An attacker can retrieve password hashes character by character, or obtain session tokens and private keys, enabling credential theft and potential authentication bypass or impersonation. The confidentiality impact is high; there is no integrity or availability impact per the CVSS vector.

Attack surface

The flaw is reachable over the network via the Webfinger protocol endpoint, with no authentication or user interaction required (CVSS vector AV:N/AC:L/PR:N/UI:N). Any exposed OpenAM instance running a vulnerable version is a candidate.

Exploitation

The record is not listed in CISA KEV, but EPSS is very high (0.76385, 99.5th percentile) and references are tagged Exploit, indicating public exploit information exists. No ransomware usage is documented.

What to do

  • Upgrade ForgeRock OpenAM to version 13.5.1 or later, which contains the fix.
  • If immediate upgrade is not possible, restrict network access to the Webfinger endpoint to trusted sources only.
  • Review and harden LDAP query construction to use parameterized or escaped inputs, and validate all Webfinger input.
  • Rotate any credentials, session tokens, or private keys that may have been exposed on vulnerable instances.
  • Monitor vendor advisories and apply any additional patches or workarounds ForgeRock publishes.

Detection

  • Inspect Webfinger request logs for LDAP filter metacharacters such as parentheses, asterisks, and boolean operators in user-supplied parameters.
  • Alert on anomalous or repeated Webfinger requests that resemble character-by-character extraction patterns.
  • Monitor LDAP server logs for unusual queries or high volumes of filter-based lookups originating from OpenAM.
  • Audit access to sensitive attributes (password hashes, session tokens, private keys) and alert on unexpected reads.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-29156 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-35464ForgeRock AM JATO deserialization remote code executionForgeRock Access Management (AM) server before 7.0 deserializes untrusted data from the jato.pageSession parameter on multiple pages, a flaw inherite…KEVEPSS 100%analysed7.5CVE-2016-10097Forgerock openam xml external entity (xxe) vulnerabilityXML External Entity (XXE) Vulnerability in /SSOPOST/metaAlias/%realm%/idpv2 in OpenAM - Access Management 10.1.0 allows remote attackers to read arbi…EPSS 2.5%6.1CVE-2017-14394Forgerock access management open redirect vulnerabilityOAuth 2.0 Authorization Server of ForgeRock Access Management (OpenAM) 13.5.0-13.5.1 and Access Management (AM) 5.0.0-5.1.1 does not correctly valida…EPSS 0.79%6.1CVE-2017-14395Forgerock access management cross-site scripting vulnerabilityAuth 2.0 Authorization Server of ForgeRock Access Management (OpenAM) 13.5.0-13.5.1 and Access Management (AM) 5.0.0-5.1.1 does not correctly validat…EPSS 0.79%3.5CVE-2014-7246Forgerock openam improper input validation vulnerabilityThe Core Server in OpenAM 9.5.3 through 9.5.5, 10.0.0 through 10.0.2, 10.1.0-Xpress, and 11.0.0 through 11.0.2, when deployed on a multi-server netwo…EPSS 1.1%10.0CVE-2025-20337Cisco ISE API input validation flaw allows unauthenticated root RCECisco ISE and ISE-PIC fail to properly validate user-supplied input in a specific API, letting an unauthenticated remote attacker execute arbitrary c…KEVEPSS 68%analysed10.0CVE-2025-20281Cisco ISE API unauthenticated remote code executionCisco ISE and ISE-PIC fail to properly validate user-supplied input in a specific API, allowing a crafted request to reach the underlying operating s…KEVEPSS 98%analysed7.2CVE-2022-43769Hitachi Vantara Pentaho BA Server Spring Template InjectionHitachi Vantara Pentaho Business Analytics Server before 9.4.0.1 and 9.3.0.2, including 8.3.x, allows certain web services to set property values con…KEVEPSS 98%analysed

Source: NIST National Vulnerability Database (record CVE-2021-29156), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.