Loading
The REST APIs in ForgeRock AM before 5.5.0 include SSOToken IDs as part of the URL, which allows attackers to obtain sensitive information by finding an ID value in a log file.
Use CWE-200, Forgerock vendor hub and Access Management product page to widen CVE-2018-7272 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2021-35464, CVE-2022-3748 and CVE-2021-37154 for nearby disclosures in the same product family.