CVE-2021-29156 | ForgeRock OpenAM up to 13.5.0 Webfinger Protocol ldap injection (EDB-50480)
A vulnerability classified as critical has been found in ForgeRock OpenAM up to 13.5.0. This affects an unknown part of the component Webfinger Protocol Handler. The manipulation leads to ldap injection.
This vulnerability is uniquely identified as CVE-2021-29156. Access to the local network is required for this attack. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.