In ForgeRock Access Management (AM) before 7.0.2, the SAML2 implementation allows XML injection, potentially enabling a fraudulent SAML 2.0 assertion.
https://www.forgerock.com/platform/access-management
https://backstage.forgerock.com/knowledge/kb/article/a55763454