Loading
In ForgeRock Access Management (AM) before 7.0.2, the SAML2 implementation allows XML injection, potentially enabling a fraudulent SAML 2.0 assertion.
Use CWE-91, Forgerock vendor hub and Access Management product page to widen CVE-2021-37154 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2021-35464, CVE-2022-3748 and CVE-2021-37153 for nearby disclosures in the same product family.