ZeroHour
The Recordpublished ()ingested

ACSC: Australian organizations compromised through ForgeRock vulnerability

criticalVulnerability exploited in the wildimportance 60CVE-2021-35464

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2021-35464
Java Deserialization RCE in ForgeRock Access Management (AM)

ForgeRock Access Management (AM) Core Server contains a Java deserialization flaw (CWE-502, deserialization of untrusted data) that allows remote code execution. An attacker triggers it by sending a specially crafted HTTP request carrying malicious serialized data to one of three web endpoints: /ccversion/Version, /ccversion/Masthead, or /ccversion/ButtonFrame. Successful exploitation executes arbitrary code in the context of the AM service account, which per the vendor is typically a non-root user, so the attacker gains the privileges of the application process on that server. Any organization running ForgeRock AM Core Server is affected, especially where the /ccversion/ endpoints are reachable by untrusted networks. The flaw is being actively exploited in the wild: it was added to CISA's Known Exploited Vulnerabilities catalog on 2021-11-03 with known ransomware use, EPSS assigns a 100% probability of exploitation within 30 days, and no public PoC is tracked in the source data.

Do: Apply ForgeRock's update per vendor instructions (the CISA KEV required action), prioritizing internet-facing AM servers. As an interim mitigation, block or restrict access to the /ccversion/ endpoints (e.g., /ccversion/*) at a reverse proxy or WAF, and ensure AM runs under a non-root service account. Because ransomware use is known, review access logs for requests to /ccversion/Version, /ccversion/Masthead, and /ccversion/ButtonFrame and treat any exposed, unpatched host as potentially compromised.

9.8100% KEV ransomware PoC ×3
  • ForgeRock Access Management (AM) Core Server
moderate≈1,000–10,000 internet-exposed ForgeRock AM/OpenAM servers, with additional uncounted internal deployments
Full article292 words · extracted from therecord.media · click to collapse

Australia's main cyber-security agency said on Friday that it identified a number of Australian organizations that have been compromised through the exploitation of a vulnerability in ForgeRock OpenAM, an open-source application used by large corporations as an identity access management solution across internal applications.

The vulnerability, tracked as CVE-2021-35464, was discovered and disclosed on June 29, last month, by Michael Stepankin, a security researcher at PortSwigger.

Described as a pre-authentication remote code execution, or a pre-auth RCE, this bug can be exploited to run malicious code OpenAM or ForgeRock Access Management platforms without needing to provide valid credentials before launching an attack.

Ten days after Sepankin disclosed the bug, it appears that the details provided in his write-up were enough for threat actors to put together a working exploit.

In a security alert published last Friday, the Australian Cyber-Security Center (ACSC) said it received reports of this vulnerability being used to compromise Australian organizations.

"The ACSC has observed actors exploiting this vulnerability to compromise multiple hosts and deploy additional malware and tools," the agency said.

The ACSC has advised companies that use the platform inside their networks to apply patches released by ForgeRock on June 29.

  • Vulnerable versions: ForgeRock OpenAM 6.x branches.
  • Fixed version: ForgeRock OpenAM 7.x branch.

The US Cybersecurity and Infrastructure Security Agency has echoed the ACSC's alert earlier today, encouraging companies to deploy patches as soon as possible.

Forge ahead with applying a critical ForgeRock Access Management patch to protect against a pre-auth #RCE vulnerability (CVE-2021-35464) being exploited in the wild. https://t.co/REBRnSx4TC. #Cybersecurity #InfoSec

— CISA Cyber (@CISACyber) July 12, 2021

The ForgeRock zero-day marks the second actively exploited bug disclosed last Friday after Microsoft found a similar vulnerability being exploited in SolarWinds Serv-U systems.

Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/acsc-australian-organizations-compromised-through-forgerock-zero-day