Openidentityplatform

Openam

32 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.23%
  • Veröffentlicht 03.10.2026 12:14:45
  • Zuletzt bearbeitet 06.10.2026 15:18:12

OpenAM before 16.1.3 contains a server-side request forgery vulnerability that allows attackers able to register or modify OAuth 2.0 clients to make OpenAM fetch internal resources via an unvalidated jwks_uri. Attackers can trigger unauthenticated fe...

  • EPSS 0.25%
  • Veröffentlicht 03.10.2026 12:14:44
  • Zuletzt bearbeitet 06.10.2026 15:18:12

OpenAM before 16.1.3 contains an improper authorization vulnerability that allows delegated administrators to destroy sessions outside their realms because realm checks use the requester's realm. Authenticated accounts holding the iplanet-am-session-...

  • EPSS 0.26%
  • Veröffentlicht 03.10.2026 12:14:44
  • Zuletzt bearbeitet 06.10.2026 15:18:12

OpenAM before 16.1.3 contains an authorization bypass vulnerability in the sessions REST endpoint query operation that allows realm administrators to list sessions of every realm. Attackers holding delegated RealmAdmin privileges can supply a _queryF...

  • EPSS 0.2%
  • Veröffentlicht 03.10.2026 12:14:43
  • Zuletzt bearbeitet 06.10.2026 17:17:17

OpenAM before 16.1.3 applies its OAuth2 Provider PKCE enforcement only to authorization requests whose response_type is exactly code, so codes issued through OpenID Connect hybrid flows (code token, code id_token, code token id_token) carry no bound ...

  • EPSS 0.1%
  • Veröffentlicht 03.10.2026 12:14:43
  • Zuletzt bearbeitet 06.10.2026 15:18:12

OpenAM before 16.1.3 contains an open redirect vulnerability that allows unauthenticated attackers to redirect users by supplying an unverified id_token_hint to the /oauth2/connect/endSession endpoint. Attackers can name any realm client in a forged ...

  • EPSS 0.16%
  • Veröffentlicht 03.10.2026 12:14:42
  • Zuletzt bearbeitet 06.10.2026 15:18:12

OpenAM before 16.1.3 contains an email content injection vulnerability that allows unauthenticated attackers to control notification email wording via the forgotPassword and register actions on /json/{realm}/users. Attackers can supply subject and me...

  • EPSS 0.16%
  • Veröffentlicht 03.10.2026 12:14:41
  • Zuletzt bearbeitet 06.10.2026 15:18:12

OpenAM before 16.1.3 contains a latent cross-site scripting defect that places the SAML message, relay state and target URL unencoded into the load-balancer cookie bounce auto-submit page. If reachable with cookieHashRedirectEnabled set, crafted requ...

  • EPSS 0.46%
  • Veröffentlicht 03.10.2026 12:14:40
  • Zuletzt bearbeitet 06.10.2026 15:18:12

OpenAM before 16.1.3 contains an unauthenticated arbitrary class instantiation vulnerability in the legacy JAX-RPC SOAP interface that allows remote attackers to load classes without authentication. Attackers can send SOAP requests to /jaxrpc/* with ...

  • EPSS 0.17%
  • Veröffentlicht 03.10.2026 12:14:39
  • Zuletzt bearbeitet 06.10.2026 17:17:17

OpenAM before 16.1.3 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject script by supplying crafted parameters rendered unencoded on the OAuth2 authorization error page. Attackers can lure victims ...

  • EPSS 0.33%
  • Veröffentlicht 15.09.2026 09:57:53
  • Zuletzt bearbeitet 23.09.2026 18:21:42

Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, AuthorizationCodeGrantTypeHandler requires a code_verifier only when the realm-wide codeVerifierEnforced setting is enabled, even when an authorization code stores a c...