VYPR

Maven package

org.openidentityplatform.openam/openam-core

pkg:maven/org.openidentityplatform.openam/openam-core

Vulnerabilities (2)

  • CVE-2026-44202MedSep 15, 2026
    affected < 16.1.1fixed 16.1.1

    Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the /sessionservice addSessionListener operation allows an authenticated user to register an arbitrary notification URL without requiring an administrative or application client token. SessionReque

  • CVE-2022-34298MedJun 23, 2022
    affected < 14.6.6fixed 14.6.6

    The NT auth module in OpenAM before 14.6.6 allows a "replace Samba username attack."