CVE-2024-25566: ForgeRock Access Management

Medium severity, CVSS 6.1. EPSS: 0.2% chance of exploitation in the next 30 days.

An Open-Redirect vulnerability exists in PingAM where well-crafted requests may cause improper validation of redirect URLs. This could allow an attacker to redirect end-users to malicious sites under their control, simplifying phishing attacks

Affected products

  • ForgeRock Access Management: up to and including 7.0.2; from 7.1.0, up to and including 7.1.4; from 7.2.0, up to and including 7.2.2; version 7.3.0 only; version 7.3.1 only; version 7.4.0 only; …

Published 2024-10-29. Last modified 2026-06-17.