3.5
CVSSv2

CVE-2014-7246

Published: 14/11/2014 Updated: 10/02/2015
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
VMScore: 312
Vector: AV:N/AC:M/Au:S/C:N/I:N/A:P

Vulnerability Summary

The Core Server in OpenAM 9.5.3 up to and including 9.5.5, 10.0.0 up to and including 10.0.2, 10.1.0-Xpress, and 11.0.0 up to and including 11.0.2, when deployed on a multi-server network, allows remote authenticated users to cause a denial of service (infinite loop) via a crafted cookie in a request.

Vulnerable Product Search on Vulmon Subscribe to Product

forgerock openam 10.0.0

forgerock openam 10.0.1

forgerock openam 10.0.2

forgerock openam 10.1.0

forgerock openam 9.5.3

forgerock openam 9.5.5

forgerock openam 11.0.0

forgerock openam 11.0.2

forgerock openam 9.5.4

forgerock openam 11.0.1