Critical severity9.8NVD Advisory· Published Aug 25, 2021· Updated Jun 17, 2026
CVE-2021-37154
CVE-2021-37154
Description
In ForgeRock Access Management (AM) before 7.0.2, the SAML2 implementation allows XML injection, potentially enabling a fraudulent SAML 2.0 assertion.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4cpe:2.3:a:forgerock:access_management:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:forgerock:access_management:*:*:*:*:*:*:*:*range: <7.0.2
- (no CPE)range: <7.0.2
- ForgeRock/Access Managementdescription
Patches
Vulnerability mechanics
References
2- backstage.forgerock.com/knowledge/kb/article/a55763454nvdVendor Advisory
- www.forgerock.com/platform/access-managementnvdProductVendor Advisory
News mentions
0No linked articles in our index yet.