Maven package
org.openidentityplatform.openam/openam-core
pkg:maven/org.openidentityplatform.openam/openam-core
Vulnerabilities (2)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-44202 | Med | — | < 16.1.1 | 16.1.1 | Sep 15, 2026 | Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the /sessionservice addSessionListener operation allows an authenticated user to register an arbitrary notification URL without requiring an administrative or application client token. SessionReque | |
| CVE-2022-34298 | Med | 5.3 | < 14.6.6 | 14.6.6 | Jun 23, 2022 | The NT auth module in OpenAM before 14.6.6 allows a "replace Samba username attack." |
- affected < 16.1.1fixed 16.1.1
Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the /sessionservice addSessionListener operation allows an authenticated user to register an arbitrary notification URL without requiring an administrative or application client token. SessionReque
- affected < 14.6.6fixed 14.6.6
The NT auth module in OpenAM before 14.6.6 allows a "replace Samba username attack."