{"id":"CVE-2021-35464","vendor_project":"ForgeRock","product":"Access Management (AM)","vulnerability_name":"ForgeRock Access Management (AM) Core Server Remote Code Execution Vulnerability","date_added":"2021-11-03","due_date":"2021-11-17","known_ransomware_use":"Known","short_description":"ForgeRock Access Management (AM) Core Server allows an attacker who sends a specially crafted HTTP request to one of three endpoints (/ccversion/Version, /ccversion/Masthead, or /ccversion/ButtonFrame) to execute code in the context of the current user (unless ForgeRock AM is running as root user, which the vendor does not recommend).","required_action":"Apply updates per vendor instructions.","cwes":"CWE-502","cvss_version":"3.1","cvss_severity":"CRITICAL","cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","nvd_published":"2021-07-22","nvd_status":"Analyzed","epss":0.99999,"epss_percentile":0.99994,"cvss_score":9.8,"days_published_to_kev":104,"source":"https://data.cybermax-tools.workers.dev/cve/CVE-2021-35464","by":"CyberMax"}