CVE Watchtower


← Back to CVE List

CVE-2021-35464NVD

Vulnerability Summary

ForgeRock AM server before 7.0 has a Java deserialization vulnerability in the jato.pageSession parameter on multiple pages. The exploitation does not require authentication, and remote code execution can be triggered by sending a single crafted /ccversion/* request to the server. The vulnerability exists due to the usage of Sun ONE Application Framework (JATO) found in versions of Java 8 or earlier
Severity Level
UNKNOWN
Published Date
Jul 22, 2021
Last Modified
Oct 21, 2025
Exploitation Status
ACTIVE
EPSS Score (30-Day)
Data Pending
Root Weakness (CWE)
N/A