VYPR

Openam

by Openidentityplatform

Source repositories

CVEs (5)

  • CVE-2026-33439CriApr 7, 2026
    risk 0.58cvss 9.8epss 0.10

    Open Access Management (OpenAM) is an access management solution. Prior to 16.0.6, OpenIdentityPlatform OpenAM is vulnerable to pre-authentication Remote Code Execution (RCE) via unsafe Java deserialization of the jato.clientSession HTTP parameter. This bypasses the…

  • CVE-2023-37471CriJul 20, 2023
    risk 0.52cvss 9.1epss 0.01

    Open Access Management (OpenAM) is an access management solution that includes Authentication, SSO, Authorization, Federation, Entitlements and Web Services Security. OpenAM up to version 14.7.2 does not properly validate the signature of SAML responses received as part of the…

  • CVE-2024-41667HigJul 24, 2024
    risk 0.50cvss 8.8epss 0.04

    OpenAM is an open access management solution. In versions 15.0.3 and prior, the `getCustomLoginUrlTemplate` method in RealmOAuth2ProviderSettings.java is vulnerable to template injection due to its usage of user input. Although the developer intended to implement a custom URL…

  • CVE-2026-46623higJun 26, 2026
    risk 0.45cvss epss

    ## Summary **Description** An Unverified Password Change (CWE-620) and Use of Weak Credentials (CWE-1391) issue in OpenAM's OAuth2 authentication module silently rewrites a local user's password to the literal string of their username on OAuth2 re-login of an existing account.…

  • CVE-2022-34298MedJun 23, 2022
    risk 0.28cvss 5.3epss 0.03

    The NT auth module in OpenAM before 14.6.6 allows a "replace Samba username attack."