← Vulnerability feed

Vulnerability record · CVE-2024-25566 · published 29 October 2024

CVE-2024-25566: Forgerock access management open redirect vulnerability

Forgerock · Access Management

An Open-Redirect vulnerability exists in PingAM where well-crafted requests may cause improper validation of redirect URLs. This could allow an attacker to redirect end-users to malicious sites under their control, simplifying phishing attacks

5.1 CVSS 4.0 Medium EPSS 0.23% · top 87.6% CWE-601 · Open redirect
5.1CVSS 4.0 base score
0.23%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

An Open-Redirect vulnerability exists in PingAM where well-crafted requests may cause improper validation of redirect URLs. This could allow an attacker to redirect end-users to malicious sites under their control, simplifying phishing attacks

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-25566 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-35464ForgeRock AM JATO deserialization remote code executionForgeRock Access Management (AM) server before 7.0 deserializes untrusted data from the jato.pageSession parameter on multiple pages, a flaw inherite…KEVEPSS 100%analysed9.8CVE-2023-0582Forgerock access management path traversal vulnerabilityImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ForgeRock Access Management allows Authorization Bypa…EPSS 0.78%9.8CVE-2022-3748Forgerock access management improper authorization vulnerabilityImproper Authorization vulnerability in ForgeRock Inc. Access Management allows Authentication Bypass. This issue affects Access Management: from 6.5…EPSS 0.91%9.8CVE-2021-4201Forgerock access management improper access control vulnerabilityMissing access control in ForgeRock Access Management 7.1.0 and earlier versions on all platforms allows remote unauthenticated attackers to hijack s…EPSS 2.0%9.8CVE-2021-37154Forgerock access management xml injection vulnerabilityIn ForgeRock Access Management (AM) before 7.0.2, the SAML2 implementation allows XML injection, potentially enabling a fraudulent SAML 2.0 assertion.EPSS 1.4%9.8CVE-2021-37153Forgerock access management vulnerabilityForgeRock Access Management (AM) before 7.0.2, when configured with Active Directory as the Identity Store, has an authentication-bypass issue.EPSS 1.2%6.5CVE-2022-24669Forgerock access management missing authorization vulnerabilityIt may be possible to gain some details of the deployment through a well-crafted attack. This may allow that data to be used to probe internal networ…EPSS 0.40%6.5CVE-2022-24670Forgerock access management information exposure vulnerabilityAn attacker can use the unrestricted LDAP queries to determine configuration entriesEPSS 0.60%

Source: NIST National Vulnerability Database (record CVE-2024-25566), CISA KEV, FIRST EPSS (scores of 2026-10-03). This page is refreshed as NVD updates the record.