An Open-Redirect vulnerability exists in PingAM where well-crafted requests may cause improper validation of redirect URLs. This could allow an attacker to redirect end-users to malicious sites under their control, simplifying phishing attacks
| Software | From | Fixed in |
|---|---|---|
| forgerock / access_management | 7.3.0 | 7.3.0.x |
| forgerock / access_management | 7.3.1 | 7.3.1.x |
| forgerock / access_management | 7.4.0 | 7.4.0.x |
| forgerock / access_management | 7.4.1 | 7.4.1.x |
| forgerock / access_management | 7.5.0 | 7.5.0.x |
| forgerock / access_management | 7.2.0 | 7.2.2.x |
| forgerock / access_management | 7.1.0 | 7.1.4.x |
| forgerock / access_management | - | 7.0.2.x |