Openidentityplatform

Openam

32 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.4%
  • Veröffentlicht 15.09.2026 09:57:08
  • Zuletzt bearbeitet 23.09.2026 18:19:19

Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the private_key_jwt client authentication path uses ClientJwksResolverCache without reliably binding a cached jwks_uri resolver and verified assertion to the expected ...

  • EPSS 0.35%
  • Veröffentlicht 15.09.2026 09:56:24
  • Zuletzt bearbeitet 23.09.2026 18:21:42

Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, GroovySandboxValueFilter permits an authenticated server-side script author to escape the scripting sandbox despite the default class allow and deny lists. A user such...

  • EPSS 0.36%
  • Veröffentlicht 15.09.2026 09:55:47
  • Zuletzt bearbeitet 23.09.2026 18:21:42

Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, IdentityResourceV1.queryCollection() passes the _queryId parameter from /json/{realm}/users to CrestQuery with escapeQueryId disabled, bypassing protection added for C...

  • EPSS 0.21%
  • Veröffentlicht 15.09.2026 09:54:53
  • Zuletzt bearbeitet 30.09.2026 17:43:24

Open Access Management (OpenAM) is an access management solution. From 13.0.0 until 16.1.2, the OAuth2 authorize endpoint's display=wap consent page reflects request-derived values through ConsentRequiredResource and wap/authorize.ftl without HTML es...

  • EPSS 0.51%
  • Veröffentlicht 15.09.2026 09:53:41
  • Zuletzt bearbeitet 23.09.2026 18:21:42

Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, WebAuthnAuthentication loads a serialized AuthenticatorImpl object graph from the configured userAttribute through loadAuthenticators without an ObjectInputFilter. Exp...

  • EPSS 0.55%
  • Veröffentlicht 15.09.2026 09:52:58
  • Zuletzt bearbeitet 23.09.2026 18:21:42

Open Access Management (OpenAM) is an access management solution. Prior to 16.1.2, WebAuthnAuthentication.deserialize applies an ObjectInputFilter that allows every serialized object at depth greater than 1 and therefore constrains only an Authentica...

  • EPSS 0.49%
  • Veröffentlicht 15.09.2026 09:52:08
  • Zuletzt bearbeitet 23.09.2026 18:19:19

Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the OAuth2 authentication module updates an existing local account with profile attributes that can include userPassword and inetUserStatus, rewriting the password to ...

  • EPSS 0.58%
  • Veröffentlicht 15.09.2026 09:51:25
  • Zuletzt bearbeitet 25.09.2026 14:23:59

Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, MSISDNValidation in the MSISDN authentication module concatenates the request-supplied MSISDN value into an LDAP search filter without escaping, while the default empt...

  • EPSS 0.32%
  • Veröffentlicht 15.09.2026 09:50:24
  • Zuletzt bearbeitet 23.09.2026 18:21:42

Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, OAuthTokenStore reads caller-supplied token identifiers from the shared Core Token Store (CTS) without an OAuth-only namespace, and OAuthAdapter accepts a row whose BL...

  • EPSS 0.52%
  • Veröffentlicht 15.09.2026 09:49:34
  • Zuletzt bearbeitet 30.09.2026 17:43:24

Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the anonymous Push Notification SNS callback handled by SnsMessageResource falls back to a CTS predicate blob after a messageId expires from the in-memory dispatcher, ...