CVE-2017-14395: ForgeRock Access Management
Medium severity, CVSS 6.1. EPSS: 0.8% chance of exploitation in the next 30 days.
Auth 2.0 Authorization Server of ForgeRock Access Management (OpenAM) 13.5.0-13.5.1 and Access Management (AM) 5.0.0-5.1.1 does not correctly validate redirect_uri for some invalid requests, which allows attackers to execute a script in the user's browser via reflected XSS.
Affected products
- ForgeRock Access Management: from 5.0.0, up to and including 5.1.1
- ForgeRock Openam: from 13.5.0, up to and including 13.5.1
Published 2019-06-19. Last modified 2026-06-17.