CVE-2021-35464Disclosure(forgerock / access_management)

LOWCVSS 9.8 · CRITICALCISA KEV

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

ForgeRock AM server before 7.0 has a Java deserialization vulnerability in the jato.pageSession parameter on multiple pages. The exploitation does not require authentication, and remote code execution can be triggered by sending a single crafted /ccversion/* request to the server. The vulnerability exists due to the usage of Sun ONE Application Framework (JATO) found in versions of Java 8 or earlier

1.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2021-11-17. Apply updates per vendor instructions.

Weakness type (CWE)
CWE-502

Priority

LOW

Exploitation

ACTIVE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • access_management
  • openam

Threat summary

  • Public PoC is present in monitored signal
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-04-07); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
access_managementopenam

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-04-07: 1Mentions · 2026-04-12: 1PoC Mentioned / Linked · 2026-04-07: 1Technical Details · 2026-04-07: 1Technical Details · 2026-04-12: 104-0704-12
Signal classification1 categories
Disclosure
2100.0%
Referenced assets1 URL
By indicator
Full discourse2 posts
  • Qubit@q810034
    Disclosure

    CVE-2026-33439 OpenAM pre-auth RCE , CVE-2021-35464 deserialization bypass for newer JDKs with command echo. https://t.co/ahqPtr2C69

    Post summary

    The tweet reports two CVEs—CVE-2026-33439 in OpenAM as a pre-authentication remote code execution vulnerability, and CVE-2021‑35464 as a deserialization bypass involving command echo—without evidence of active exploitation or mitigation information.

    00000108
    47 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-33439: Pre-Authentication Remote Code E... OpenAM's jato.clientSession parameter bypasses CVE-2021-35464 whitelist fix—pre-auth RCE via Java deserialization on an... https://zerodaysignal.com/vulnerability/CVE-2026-33439 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    CVE‑2026‑33439 is a pre‑authentication remote code execution flaw in OpenAM, enabled by a Java deserialization bypass that defeats a whitelist fix. The linked article likely contains further details and potentially a PoC.

    00000101
    204 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appforgerockaccess_management---
Appforgerockopenam---

Explore more