cbcvebase.

Openidentityplatform Openam vulnerabilities

33 known vulnerabilities affecting openidentityplatform/openam.

Total CVEs
33
CISA KEV
1
actively exploited
Public exploits
4
Exploited in wild
1
Severity breakdown
CRITICAL9HIGH13MEDIUM11

Vulnerabilities

Page 2 of 2
CVE-2026-44793P3HIGHCVSS 7.0fixed in 16.1.12026-09-15
CVE-2026-44793 [HIGH] CWE-79 CVE-2026-44793: Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, certain federatio Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, certain federation endpoints in a non-default clustered configuration inconsistently encode user-supplied parameters rendered into HTML in the SAML2 cluster cookie-hash redirect path. An unauthenticated attacker can induce a user to follow a crafted request and execute s
nvd
CVE-2026-53660P3HIGHCVSS 7.4fixed in 16.1.12026-09-15
CVE-2026-53660 [HIGH] CWE-1004 CVE-2026-53660: Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the default confi Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the default configuration initializes the iPlanetDirectoryPro SSO cookie with HttpOnly disabled and without a protective SameSite default, and OAuth and OpenID Connect consent flows reuse that cookie through CsrfProtection as a CSRF token. When combined with same-origi
nvd
CVE-2026-105119P3MEDIUMCVSS 6.8fixed in 16.1.32026-10-03
CVE-2026-105119 [MEDIUM] CWE-285 CVE-2026-105119: OpenAM before 16.1.3 applies its OAuth2 Provider PKCE enforcement only to authorization requests who OpenAM before 16.1.3 applies its OAuth2 Provider PKCE enforcement only to authorization requests whose response_type is exactly code, so codes issued through OpenID Connect hybrid flows (code token, code id_token, code token id_token) carry no bound challenge. An attacker who intercepts such a code can redeem it for a public client's tokens with a
nvd
CVE-2026-44202P3MEDIUMCVSS 5.3fixed in 16.1.12026-09-15
CVE-2026-44202 [MEDIUM] CWE-918 CVE-2026-44202: Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the /sessionservi Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the /sessionservice addSessionListener operation allows an authenticated user to register an arbitrary notification URL without requiring an administrative or application client token. SessionRequestHandler passes the attacker-controlled destination to the session lis
nvd
CVE-2026-62280P4MEDIUMCVSS 6.1v>= 13.0.0, < 16.1.22026-09-15
CVE-2026-62280 [MEDIUM] CWE-79 CVE-2026-62280: Open Access Management (OpenAM) is an access management solution. From 13.0.0 until 16.1.2, the OAut Open Access Management (OpenAM) is an access management solution. From 13.0.0 until 16.1.2, the OAuth2 authorize endpoint's display=wap consent page reflects request-derived values through ConsentRequiredResource and wap/authorize.ftl without HTML escaping. An attacker can induce a user with an active OpenAM session to follow a crafted authorization
nvd
CVE-2026-105117P4MEDIUMCVSS 6.1fixed in 16.1.32026-10-03
CVE-2026-105117 [MEDIUM] CWE-20 CVE-2026-105117: OpenAM before 16.1.3 contains an email content injection vulnerability that allows unauthenticated a OpenAM before 16.1.3 contains an email content injection vulnerability that allows unauthenticated attackers to control notification email wording via the forgotPassword and register actions on /json/{realm}/users. Attackers can supply subject and message fields to send phishing mail from the organisation's configured From address, or abuse registe
nvd
CVE-2026-105122P4MEDIUMCVSS 5.4fixed in 16.1.32026-10-03
CVE-2026-105122 [MEDIUM] CWE-918 CVE-2026-105122: OpenAM before 16.1.3 contains a server-side request forgery vulnerability that allows attackers able OpenAM before 16.1.3 contains a server-side request forgery vulnerability that allows attackers able to register or modify OAuth 2.0 clients to make OpenAM fetch internal resources via an unvalidated jwks_uri. Attackers can trigger unauthenticated fetches through client-authentication and ID-token validation to probe internal hosts, metadata endpo
nvd
CVE-2026-105120P4MEDIUMCVSS 4.9fixed in 16.1.32026-10-03
CVE-2026-105120 [MEDIUM] CWE-200 CVE-2026-105120: OpenAM before 16.1.3 contains an authorization bypass vulnerability in the sessions REST endpoint qu OpenAM before 16.1.3 contains an authorization bypass vulnerability in the sessions REST endpoint query operation that allows realm administrators to list sessions of every realm. Attackers holding delegated RealmAdmin privileges can supply a _queryFilter naming another realm to disclose usernames, universal IDs, and session handles across tenant
nvd
CVE-2022-34298P4MEDIUMCVSS 5.3fixed in 14.6.62022-06-23
CVE-2022-34298 [MEDIUM] CVE-2022-34298: The NT auth module in OpenAM before 14.6.6 allows a "replace Samba username attack." The NT auth module in OpenAM before 14.6.6 allows a "replace Samba username attack."
nvd
CVE-2026-105114P4MEDIUMCVSS 6.1fixed in 16.1.32026-10-03
CVE-2026-105114 [MEDIUM] CWE-79 CVE-2026-105114: OpenAM before 16.1.3 contains a reflected cross-site scripting vulnerability that allows unauthentic OpenAM before 16.1.3 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject script by supplying crafted parameters rendered unencoded on the OAuth2 authorization error page. Attackers can lure victims to a crafted /oauth2/authorize link with repeated parameters to run JavaScript in the OpenAM origin,
nvd
CVE-2026-105116P4MEDIUMCVSS 6.1fixed in 16.1.32026-10-03
CVE-2026-105116 [MEDIUM] CWE-79 CVE-2026-105116: OpenAM before 16.1.3 contains a latent cross-site scripting defect that places the SAML message, rel OpenAM before 16.1.3 contains a latent cross-site scripting defect that places the SAML message, relay state and target URL unencoded into the load-balancer cookie bounce auto-submit page. If reachable with cookieHashRedirectEnabled set, crafted requests could execute script in the OpenAM origin, though an unrelated HTTP 500 failure prevents exploi
nvd
CVE-2026-105121P4MEDIUMCVSS 4.9fixed in 16.1.32026-10-03
CVE-2026-105121 [MEDIUM] CWE-285 CVE-2026-105121: OpenAM before 16.1.3 contains an improper authorization vulnerability that allows delegated administ OpenAM before 16.1.3 contains an improper authorization vulnerability that allows delegated administrators to destroy sessions outside their realms because realm checks use the requester's realm. Authenticated accounts holding the iplanet-am-session-destroy-sessions attribute can supply a target session identifier or handle to forcibly log out use
nvd
CVE-2026-105118P4MEDIUMCVSS 4.7fixed in 16.1.32026-10-03
CVE-2026-105118 [MEDIUM] CWE-347 CVE-2026-105118: OpenAM before 16.1.3 contains an open redirect vulnerability that allows unauthenticated attackers t OpenAM before 16.1.3 contains an open redirect vulnerability that allows unauthenticated attackers to redirect users by supplying an unverified id_token_hint to the /oauth2/connect/endSession endpoint. Attackers can name any realm client in a forged hint to redirect victims to any registered post-logout URI, enabling phishing that borrows the Open
nvd
Openidentityplatform Openam vulnerabilities | cvebase