← Vulnerability feed

Vulnerability record · CVE-2022-3748 · published 14 April 2023

CVE-2022-3748: Forgerock access management improper authorization vulnerability

Forgerock · Access Management

Improper Authorization vulnerability in ForgeRock Inc. Access Management allows Authentication Bypass. This issue affects Access Management: from 6.5.0 through 7.2.0.

9.8 CVSS 3.1 Critical EPSS 0.91% · top 41.7% CWE-285 · Improper authorization
9.8CVSS 3.1 base score
0.91%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

Improper Authorization vulnerability in ForgeRock Inc. Access Management allows Authentication Bypass. This issue affects Access Management: from 6.5.0 through 7.2.0.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-3748 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-35464ForgeRock AM JATO deserialization remote code executionForgeRock Access Management (AM) server before 7.0 deserializes untrusted data from the jato.pageSession parameter on multiple pages, a flaw inherite…KEVEPSS 100%analysed9.8CVE-2023-0582Forgerock access management path traversal vulnerabilityImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ForgeRock Access Management allows Authorization Bypa…EPSS 0.78%9.8CVE-2021-4201Forgerock access management improper access control vulnerabilityMissing access control in ForgeRock Access Management 7.1.0 and earlier versions on all platforms allows remote unauthenticated attackers to hijack s…EPSS 2.0%9.8CVE-2021-37154Forgerock access management xml injection vulnerabilityIn ForgeRock Access Management (AM) before 7.0.2, the SAML2 implementation allows XML injection, potentially enabling a fraudulent SAML 2.0 assertion.EPSS 1.4%9.8CVE-2021-37153Forgerock access management vulnerabilityForgeRock Access Management (AM) before 7.0.2, when configured with Active Directory as the Identity Store, has an authentication-bypass issue.EPSS 1.2%6.5CVE-2022-24669Forgerock access management missing authorization vulnerabilityIt may be possible to gain some details of the deployment through a well-crafted attack. This may allow that data to be used to probe internal networ…EPSS 0.39%6.5CVE-2022-24670Forgerock access management information exposure vulnerabilityAn attacker can use the unrestricted LDAP queries to determine configuration entriesEPSS 0.58%6.5CVE-2018-7272Forgerock access management information exposure vulnerabilityThe REST APIs in ForgeRock AM before 5.5.0 include SSOToken IDs as part of the URL, which allows attackers to obtain sensitive information by finding…EPSS 0.86%

Source: NIST National Vulnerability Database (record CVE-2022-3748), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.