Openidentityplatform

Openam

32 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.25%
  • Veröffentlicht 15.09.2026 09:48:50
  • Zuletzt bearbeitet 23.09.2026 18:19:19

Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, SessionRequestHandler in the session management endpoint does not enforce ownership or privilege checks when a low-privileged authenticated user queries session inform...

  • EPSS 0.47%
  • Veröffentlicht 15.09.2026 09:48:07
  • Zuletzt bearbeitet 23.09.2026 18:19:19

Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the OAuth 2.0 and OpenID Connect authorization endpoint does not sufficiently encode user-supplied parameters before FormPostResponse.ftl and checkSession.ftl render t...

  • EPSS 0.32%
  • Veröffentlicht 15.09.2026 09:47:00
  • Zuletzt bearbeitet 25.09.2026 14:23:59

Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the /sessionservice addSessionListener operation allows an authenticated user to register an arbitrary notification URL without requiring an administrative or applicat...

  • EPSS 0.65%
  • Veröffentlicht 15.09.2026 09:45:52
  • Zuletzt bearbeitet 25.09.2026 14:23:59

Open Access Management (OpenAM) is an access management solution. Prior to 16.1.2, the pre-authentication /authservice PLL endpoint accepts a CustomCallback XML element whose className value selects an arbitrary Java class for AuthXMLUtils to load an...

  • EPSS 0.33%
  • Veröffentlicht 15.09.2026 09:45:01
  • Zuletzt bearbeitet 23.09.2026 18:21:42

Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the default configuration initializes the iPlanetDirectoryPro SSO cookie with HttpOnly disabled and without a protective SameSite default, and OAuth and OpenID Connect...

  • EPSS 0.33%
  • Veröffentlicht 15.09.2026 09:43:59
  • Zuletzt bearbeitet 30.09.2026 17:43:24

Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the Liberty Web Services SOAP receiver permits unauthenticated remote requests to write persistent entries through SOAPReceiver and DiscoveryService into a user's Libe...

  • EPSS 0.45%
  • Veröffentlicht 15.09.2026 09:42:18
  • Zuletzt bearbeitet 23.09.2026 18:21:42

Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, certain federation endpoints in a non-default clustered configuration inconsistently encode user-supplied parameters rendered into HTML in the SAML2 cluster cookie-has...

Medienbericht Exploit
  • EPSS 10.49%
  • Veröffentlicht 07.04.2026 20:46:33
  • Zuletzt bearbeitet 24.07.2026 23:10:00

Open Access Management (OpenAM) is an access management solution. Prior to 16.0.6, OpenIdentityPlatform OpenAM is vulnerable to pre-authentication Remote Code Execution (RCE) via unsafe Java deserialization of the jato.clientSession HTTP parameter. T...

  • EPSS 0.33%
  • Veröffentlicht 12.11.2025 19:15:38
  • Zuletzt bearbeitet 15.04.2026 00:35:42

Open Access Management (OpenAM) is an access management solution. In versions prior to 16.0.0, if the "claims_parameter_supported" parameter is activated, it is possible, thanks to the "oidc-claims-extension.groovy" script, to inject the value of one...

  • EPSS 3.54%
  • Veröffentlicht 24.07.2024 18:15:05
  • Zuletzt bearbeitet 15.04.2026 00:35:42

OpenAM is an open access management solution. In versions 15.0.3 and prior, the `getCustomLoginUrlTemplate` method in RealmOAuth2ProviderSettings.java is vulnerable to template injection due to its usage of user input. Although the developer intended...