CVE-2023-0582: ForgeRock Access Management

Critical severity, CVSS 9.8. EPSS: 0.8% chance of exploitation in the next 30 days.

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ForgeRock Access Management allows Authorization Bypass. This issue affects access management: before 7.3.0, before 7.2.1, before 7.1.4, through 7.0.2.

Affected products

  • ForgeRock Access Management: before 7.1.4 (fixed in 7.1.4); version 7.2.0 only

Published 2024-03-27. Last modified 2026-06-17.