VYPR

OpenAM

by OpenAM Consortium

CVEs (2)

  • CVE-2023-22320HigJan 10, 2023
    risk 0.49cvss 7.5epss 0.01

    OpenAM Web Policy Agent (OpenAM Consortium Edition) provided by OpenAM Consortium parses URLs improperly, leading to a path traversal vulnerability(CWE-22). Furthermore, a crafted URL may be evaluated incorrectly.

  • CVE-2025-8662MedSep 2, 2025
    risk 0.28cvss 4.3epss 0.00

    OpenAM (OpenAM Consortium Edition) contains a vulnerability that may cause it to malfunction as a SAML IdP due to a tampered request.This issue affects OpenAM: from 14.0.0 through 14.0.1.