Apache Struts 2 vulnerabilities and ForgeRock products

Last updated Feb 2, 2022

The purpose of this article is to provide information on whether ForgeRock products (AM/OpenAM, DS/OpenDJ, IDM/OpenIDM and IG/OpenIG) are vulnerable to the Apache™ Struts 2 issues (CVE-2018-11776 or CVE-2017-5638). These vulnerabilities allow an attacker to remotely execute code in certain circumstances.

