cbcvebase.

Openidentityplatform Openam vulnerabilities

33 known vulnerabilities affecting openidentityplatform/openam.

Total CVEs
33
CISA KEV
1
actively exploited
Public exploits
4
Exploited in wild
1
Severity breakdown
CRITICAL9HIGH13MEDIUM11

Vulnerabilities

Page 1 of 2
CVE-2021-35464P1CRITICALCVSS 9.8KEVPoCRansomwarefixed in 16.0.62021-07-22
CVE-2021-35464 [CRITICAL] CWE-502 CVE-2021-35464: ForgeRock AM server before 7.0 has a Java deserialization vulnerability in the jato.pageSession para ForgeRock AM server before 7.0 has a Java deserialization vulnerability in the jato.pageSession parameter on multiple pages. The exploitation does not require authentication, and remote code execution can be triggered by sending a single crafted /ccversion/* request to the server. The vulnerability exists due to the usage of Sun ONE Application Fr
nvd
CVE-2026-33439P1CRITICALCVSS 9.8PoCfixed in 16.0.62026-04-07
CVE-2026-33439 [CRITICAL] CVE-2026-33439: Open Access Management (OpenAM) is an access management solution. Prior to 16.0.6, OpenIdentityPlatf Open Access Management (OpenAM) is an access management solution. Prior to 16.0.6, OpenIdentityPlatform OpenAM is vulnerable to pre-authentication Remote Code Execution (RCE) via unsafe Java deserialization of the jato.clientSession HTTP parameter. This bypasses the WhitelistObjectInputStream mitigation that was applied to the jato.pageSession parameter a
nvd
CVE-2021-29156P2HIGHCVSS 7.5PoCfixed in 16.1.12021-03-25
CVE-2021-29156 [HIGH] CWE-74 CVE-2021-29156: ForgeRock OpenAM before 13.5.1 allows LDAP injection via the Webfinger protocol. For example, an una ForgeRock OpenAM before 13.5.1 allows LDAP injection via the Webfinger protocol. For example, an unauthenticated attacker can perform character-by-character retrieval of password hashes, or retrieve a session token or a private key.
nvd
CVE-2024-41667P2HIGHCVSS 8.8PoCfixed in 15.0.42024-07-24
CVE-2024-41667 [HIGH] CWE-94 CVE-2024-41667: OpenAM is an open access management solution. In versions 15.0.3 and prior, the `getCustomLoginUrlTe OpenAM is an open access management solution. In versions 15.0.3 and prior, the `getCustomLoginUrlTemplate` method in RealmOAuth2ProviderSettings.java is vulnerable to template injection due to its usage of user input. Although the developer intended to implement a custom URL for handling login to override the default OpenAM login, they did not restric
nvd
CVE-2026-62379P2CRITICALCVSS 9.8fixed in 16.1.22026-09-15
CVE-2026-62379 [CRITICAL] CWE-94 CVE-2026-62379: Open Access Management (OpenAM) is an access management solution. Prior to 16.1.2, the pre-authentic Open Access Management (OpenAM) is an access management solution. Prior to 16.1.2, the pre-authentication /authservice PLL endpoint accepts a CustomCallback XML element whose className value selects an arbitrary Java class for AuthXMLUtils to load and instantiate without verifying that it implements DSAMECallbackInterface. Default configurations ex
nvd
CVE-2026-46619P2CRITICALCVSS 9.3fixed in 16.1.12026-09-15
CVE-2026-46619 [CRITICAL] CWE-90 CVE-2026-46619: Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, MSISDNValidation Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, MSISDNValidation in the MSISDN authentication module concatenates the request-supplied MSISDN value into an LDAP search filter without escaping, while the default empty trusted-gateway list allows all traffic. In a realm where an MSISDN module is enabled in a reachabl
nvd
CVE-2026-45052P2CRITICALCVSS 9.3fixed in 16.1.12026-09-15
CVE-2026-45052 [CRITICAL] CWE-285 CVE-2026-45052: Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the Liberty Web S Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the Liberty Web Services SOAP receiver permits unauthenticated remote requests to write persistent entries through SOAPReceiver and DiscoveryService into a user's Liberty Discovery store and the shared root-realm Discovery branch. The server-side handlers bypass req
nvd
CVE-2026-62263P2CRITICALCVSS 9.2fixed in 16.1.22026-09-15
CVE-2026-62263 [CRITICAL] CWE-502 CVE-2026-62263: Open Access Management (OpenAM) is an access management solution. Prior to 16.1.2, WebAuthnAuthentic Open Access Management (OpenAM) is an access management solution. Prior to 16.1.2, WebAuthnAuthentication.deserialize applies an ObjectInputFilter that allows every serialized object at depth greater than 1 and therefore constrains only an AuthenticatorImpl root object. A pre-authentication attacker can supply a userHandle whose serialized graph h
nvd
CVE-2026-105115P2HIGHCVSS 8.6fixed in 16.1.32026-10-03
CVE-2026-105115 [HIGH] CWE-306 CVE-2026-105115: OpenAM before 16.1.3 contains an unauthenticated arbitrary class instantiation vulnerability in the OpenAM before 16.1.3 contains an unauthenticated arbitrary class instantiation vulnerability in the legacy JAX-RPC SOAP interface that allows remote attackers to load classes without authentication. Attackers can send SOAP requests to /jaxrpc/* with an unverified session identifier and a chosen class name, crashing the server, probing the classpath,
nvd
CVE-2026-45051P2CRITICALCVSS 9.2fixed in 16.1.12026-09-15
CVE-2026-45051 [CRITICAL] CWE-502 CVE-2026-45051: Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, WebAuthnAuthentic Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, WebAuthnAuthentication loads a serialized AuthenticatorImpl object graph from the configured userAttribute through loadAuthenticators without an ObjectInputFilter. Exploitation requires the WebAuthn flow to be reachable and an attacker to have previously written con
nvd
CVE-2023-37471P3CRITICALCVSS 9.8fixed in 14.7.32023-07-20
CVE-2023-37471 [CRITICAL] CWE-287 CVE-2023-37471: Open Access Management (OpenAM) is an access management solution that includes Authentication, SSO, Open Access Management (OpenAM) is an access management solution that includes Authentication, SSO, Authorization, Federation, Entitlements and Web Services Security. OpenAM up to version 14.7.2 does not properly validate the signature of SAML responses received as part of the SAMLv1.x Single Sign-On process. Attackers can use this fact to imperson
nvd
CVE-2026-48717P2CRITICALCVSS 9.1fixed in 16.1.12026-09-15
CVE-2026-48717 [CRITICAL] CWE-285 CVE-2026-48717: Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, AuthorizationCode Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, AuthorizationCodeGrantTypeHandler requires a code_verifier only when the realm-wide codeVerifierEnforced setting is enabled, even when an authorization code stores a code_challenge. Because that setting is disabled by default, an attacker who intercepts a PKCE-prote
nvd
CVE-2026-45048P3HIGHCVSS 8.5fixed in 16.1.12026-09-15
CVE-2026-45048 [HIGH] CWE-200 CVE-2026-45048: Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, SessionRequestHan Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, SessionRequestHandler in the session management endpoint does not enforce ownership or privilege checks when a low-privileged authenticated user queries session information in deployments using stateful session storage. A requester who knows a target identity identifier
nvd
CVE-2026-46623P3HIGHCVSS 7.4fixed in 16.1.12026-09-15
CVE-2026-46623 [HIGH] CWE-620 CVE-2026-46623: Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the OAuth2 authen Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the OAuth2 authentication module updates an existing local account with profile attributes that can include userPassword and inetUserStatus, rewriting the password to the username and reactivating disabled accounts. The missing OAuth.removeRestrictedAccountUpdateAttribu
nvd
CVE-2026-44203P3HIGHCVSS 8.3fixed in 16.1.12026-09-15
CVE-2026-44203 [HIGH] CWE-79 CVE-2026-44203: Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the OAuth 2.0 and Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the OAuth 2.0 and OpenID Connect authorization endpoint does not sufficiently encode user-supplied parameters before FormPostResponse.ftl and checkSession.ftl render them into HTML for the form_post response mode. An unauthenticated attacker can induce a user to open a c
nvd
CVE-2026-47426P3HIGHCVSS 7.6fixed in 16.1.12026-09-15
CVE-2026-47426 [HIGH] CWE-287 CVE-2026-47426: Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the private_key_j Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the private_key_jwt client authentication path uses ClientJwksResolverCache without reliably binding a cached jwks_uri resolver and verified assertion to the expected clientID in ClientCredentialsReader. An attacker controlling any registered client with published keys,
nvd
CVE-2026-45794P3HIGHCVSS 7.7fixed in 16.1.12026-09-15
CVE-2026-45794 [HIGH] CWE-502 CVE-2026-45794: Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the anonymous Pus Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the anonymous Push Notification SNS callback handled by SnsMessageResource falls back to a CTS predicate blob after a messageId expires from the in-memory dispatcher, treats top-level blob keys as Java class names for Class.forName, and deserializes attacker-controlled
nvd
CVE-2026-46498P3HIGHCVSS 7.6fixed in 16.1.12026-09-15
CVE-2026-46498 [HIGH] CWE-639 CVE-2026-46498: Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, OAuthTokenStore r Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, OAuthTokenStore reads caller-supplied token identifiers from the shared Core Token Store (CTS) without an OAuth-only namespace, and OAuthAdapter accepts a row whose BLOB claims to contain an OAuth token without binding the trusted CTS type or verifying integrity. An att
nvd
CVE-2025-64099P3HIGHCVSS 8.1fixed in 16.0.02025-11-12
CVE-2025-64099 [HIGH] CWE-74 CVE-2025-64099: Open Access Management (OpenAM) is an access management solution. In versions prior to 16.0.0, if th Open Access Management (OpenAM) is an access management solution. In versions prior to 16.0.0, if the "claims_parameter_supported" parameter is activated, it is possible, thanks to the "oidc-claims-extension.groovy" script, to inject the value of one's choice into a claim contained in the id_token or in the user_info. In the request of an authorize fun
nvd
CVE-2026-47424P3HIGHCVSS 7.5fixed in 16.1.12026-09-15
CVE-2026-47424 [HIGH] CWE-693 CVE-2026-47424: Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, GroovySandboxValu Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, GroovySandboxValueFilter permits an authenticated server-side script author to escape the scripting sandbox despite the default class allow and deny lists. A user such as a sub-realm RealmAdmin who can create or edit a script in an executed context can invoke operating-
nvd
Openidentityplatform Openam vulnerabilities | cvebase