{"record":"ForgeRock evidence record","url":"https://nexalign.io/vendors/forgerock","vendor":{"slug":"forgerock","name":"ForgeRock","domain":"forgerock.com","category":"iam","categoryLabel":"Identity and access management"},"lastChecked":"2026-07-22T04:18:12.872Z","coverage":{"earliest":"2017-02-03T19:00:00.000Z","latest":"2026-07-22T04:18:12.872Z"},"terms":{"isRanking":false,"isRating":false,"statesSuitability":false,"note":"This is a record of what public sources hold about a named company. It states no ranking, no rating and no suitability verdict, and none may be derived from it. An absent or small record means the public registers publish little under that name; it is not evidence that a product is secure. A larger advisory count generally reflects wider deployment and more scrutiny rather than a weaker product.","licence":"https://nexalign.io/vendors#licence","corrections":"info@nexalign.io"},"totals":{"evidenceItems":26,"kindsOfSource":4,"attributedAdvisories":11,"knownExploited":1,"registerEntriesNotAttributable":8,"practitionerThreads":0,"independentItems":4,"vendorPublishedItems":0,"shareFromSourcesTheVendorDoesNotControl":1},"sources":[{"source":"European Vulnerability Database","operator":"ENISA, European Union","classification":"authoritative","items":19,"latest":"2026-04-07T22:33:05.000Z"},{"source":"Known Exploited Vulnerabilities catalogue","operator":"CISA, United States","classification":"authoritative","items":1,"latest":"2021-11-03T00:00:00.000Z"},{"source":"National Vulnerability Database","operator":"NIST, United States Department of Commerce","classification":"authoritative","items":1,"latest":"2026-04-07T23:16:27.040Z"},{"source":"Analyst, review and reference sources","operator":"Recognised analysts, review marketplaces and technology press","classification":"independent","items":5,"latest":"2026-07-22T04:18:12.872Z"}],"advisories":{"shown":6,"total":11,"truncated":true,"items":[{"id":"CVE-2021-35464","description":"ForgeRock Access Management (AM) Core Server Remote Code Execution Vulnerability","severity":"critical","cvss":9.8,"knownExploited":true,"date":"2021-11-03T00:00:00.000Z","sources":["https://nvd.nist.gov/vuln/detail/CVE-2021-35464","https://euvd.enisa.europa.eu/vulnerability/EUVD-2021-22106"]},{"id":"CVE-2025-20628","description":"An insufficient granularity of access control vulnerability exists in PingIDM (formerly ForgeRock Identity Management) where administrators cannot properly configure access rules for Remote…","severity":"medium","cvss":6.9,"knownExploited":false,"date":"2026-04-07T23:16:27.040Z","sources":["https://nvd.nist.gov/vuln/detail/CVE-2025-20628","https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-209288"]},{"id":"CVE-2023-0582","description":"Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ForgeRock Access Management allows Authorization Bypass.","severity":"high","cvss":8.1,"knownExploited":false,"date":"2024-03-27T17:09:43.000Z","sources":["https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-12622"]},{"id":"CVE-2022-3748","description":"Improper Authorization vulnerability in ForgeRock Inc.","severity":"critical","cvss":9.8,"knownExploited":false,"date":"2023-04-14T14:06:30.000Z","sources":["https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-43104"]},{"id":"CVE-2023-1656","description":"Cleartext Transmission of Sensitive Information vulnerability in ForgeRock Inc.","severity":"high","cvss":7.5,"knownExploited":false,"date":"2023-03-29T19:55:13.000Z","sources":["https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-23885"]},{"id":"CVE-2023-0511","description":"Relative Path Traversal vulnerability in ForgeRock Access Management Java Policy Agent allows Authentication Bypass.","severity":"critical","cvss":9.1,"knownExploited":false,"date":"2023-02-28T16:26:19.000Z","sources":["https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-12557"]}]},"practitionerThreads":{"shown":0,"total":0,"truncated":false,"items":[]},"independentCoverage":{"shown":4,"total":4,"truncated":false,"items":[{"title":"ForgeRock Reviews, Ratings & Features 2023 | Gartner Peer Insights","host":"gartner.com","url":"https://www.gartner.com/reviews/market/iot-security/vendor/forgerock","date":null},{"title":"ForgeRock - Wikipedia","host":"en.wikipedia.org","url":"https://en.wikipedia.org/wiki/ForgeRock","date":null},{"title":"ForgeRock Reviews, Competitors and Pricing","host":"peerspot.com","url":"https://www.peerspot.com/products/forgerock-reviews","date":null},{"title":"What is your primary use case for ForgeRock?","host":"peerspot.com","url":"https://www.peerspot.com/questions/what-is-your-primary-use-case-for-forgerock","date":null}]},"vendorPublished":{"shown":0,"total":0,"truncated":false,"items":[]},"openQuestions":["A further 8 register entries mention ForgeRock without naming a product of ForgeRock as affected. They are excluded rather than counted as vulnerabilities.","No public practitioner discussion naming ForgeRock was found in the indexed threads. Operational experience with this product is not represented in this record.","Pricing, contract terms, notice periods and support commitments are not part of any public register. They come from the vendor and belong in a negotiation record.","Certification status such as ISO 27001, SOC 2 or BSI C5 has to be checked against the current certificate and its stated scope. A valid certificate can still exclude the product being bought."]}