oM noM Security Feeds cve
vulnerability context

CVE-2021-4201

CVSS 9.6 CRITICALEPSS 78%CWE-284

Missing access control in ForgeRock Access Management 7.1.0 and earlier versions on all platforms allows remote unauthenticated attackers to hijack sessions, including potentially admin-level sessions. This issue affects: ForgeRock Access Management 7.1 versions prior to 7.1.1; 6.5 versions prior to 6.5.4; all previous versions.

Published 2022-02-14 · last modified 2026-06-17

details

CISA KEV status
Not in catalog
CVSS v3
9.6 / CRITICAL
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
EPSS
78% percentile (score 0.0195)
CWE
CWE-284
OTX pulses
0 total, 0 recent

source mentions 1

source consensus

  • GitHub Advisories
Want the 3-bullet summary of CVE-2021-4201, plus webhook alerts when KEV is updated? Pro is $10/mo.