CVE-2014-7246

low
Published 2014-11-14 · Modified 2026-05-06
CVSS v3
CVSS v2
3.5
VIR risk
3.5

Description

The Core Server in OpenAM 9.5.3 through 9.5.5, 10.0.0 through 10.0.2, 10.1.0-Xpress, and 11.0.0 through 11.0.2, when deployed on a multi-server network, allows remote authenticated users to cause a denial of service (infinite loop) via a crafted cookie in a request.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: vultures@jpcert.or.jp — https://forgerock.org/2014/11/openam-security-advisory-201404/

vendor Authored 2026-05-27

Vendor advisory: vultures@jpcert.or.jp — http://sources.forgerock.org/changelog/openam/?cs=11248

Application impact

VendorProductVersionsFixed
forgerockopenam9.5.3
forgerockopenam9.5.4
forgerockopenam9.5.5
forgerockopenam10.0.0
forgerockopenam10.0.1
forgerockopenam10.0.2
forgerockopenam10.1.0
forgerockopenam11.0.0
forgerockopenam11.0.1
forgerockopenam11.0.2

References

CWEs

CWE-20

Verify integrity in audit chain (admin only). AS-IS.