OpenAM Consortium
Products
5- 4 CVEs
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
Recent CVEs
7| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-22320 | Hig | 0.49 | 7.5 | 0.01 | Jan 10, 2023 | OpenAM Web Policy Agent (OpenAM Consortium Edition) provided by OpenAM Consortium parses URLs improperly, leading to a path traversal vulnerability(CWE-22). Furthermore, a crafted URL may be evaluated incorrectly. | ||
| CVE-2018-0696 | Hig | 0.49 | 7.5 | 0.01 | Feb 13, 2019 | OpenAM (Open Source Edition) 13.0 and later does not properly manage sessions, which allows remote authenticated attackers to change the security questions and reset the login password via unspecified vectors. | ||
| CVE-2026-46560 | hig | 0.45 | — | — | Jun 25, 2026 | ## Summary **Description** An Improper Verification of Cryptographic Signature (CWE-347) issue in OpenAM's RADIUS authentication module allows an unauthenticated network attacker to spoof an Access-Accept response and obtain an OpenAM session for any RADIUS username, without… | ||
| CVE-2022-31735 | Med | 0.40 | 6.1 | 0.01 | Sep 15, 2022 | OpenAM Consortium Edition version 14.0.0 provided by OpenAM Consortium contains an open redirect vulnerability (CWE-601). When accessing an affected server through some specially crafted URL, the user may be redirected to an arbitrary website. | ||
| CVE-2025-8662 | Med | 0.28 | 4.3 | 0.00 | Sep 2, 2025 | OpenAM (OpenAM Consortium Edition) contains a vulnerability that may cause it to malfunction as a SAML IdP due to a tampered request.This issue affects OpenAM: from 14.0.0 through 14.0.1. | ||
| CVE-2022-34298 | Med | 0.28 | 5.3 | 0.03 | Jun 23, 2022 | The NT auth module in OpenAM before 14.6.6 allows a "replace Samba username attack." | ||
| CVE-2014-7246 | 0.00 | — | 0.01 | Nov 14, 2014 | The Core Server in OpenAM 9.5.3 through 9.5.5, 10.0.0 through 10.0.2, 10.1.0-Xpress, and 11.0.0 through 11.0.2, when deployed on a multi-server network, allows remote authenticated users to cause a denial of service (infinite loop) via a crafted cookie in a request. |
- risk 0.49cvss 7.5epss 0.01
OpenAM Web Policy Agent (OpenAM Consortium Edition) provided by OpenAM Consortium parses URLs improperly, leading to a path traversal vulnerability(CWE-22). Furthermore, a crafted URL may be evaluated incorrectly.
- risk 0.49cvss 7.5epss 0.01
OpenAM (Open Source Edition) 13.0 and later does not properly manage sessions, which allows remote authenticated attackers to change the security questions and reset the login password via unspecified vectors.
- risk 0.45cvss —epss —
## Summary **Description** An Improper Verification of Cryptographic Signature (CWE-347) issue in OpenAM's RADIUS authentication module allows an unauthenticated network attacker to spoof an Access-Accept response and obtain an OpenAM session for any RADIUS username, without…
- risk 0.40cvss 6.1epss 0.01
OpenAM Consortium Edition version 14.0.0 provided by OpenAM Consortium contains an open redirect vulnerability (CWE-601). When accessing an affected server through some specially crafted URL, the user may be redirected to an arbitrary website.
- risk 0.28cvss 4.3epss 0.00
OpenAM (OpenAM Consortium Edition) contains a vulnerability that may cause it to malfunction as a SAML IdP due to a tampered request.This issue affects OpenAM: from 14.0.0 through 14.0.1.
- risk 0.28cvss 5.3epss 0.03
The NT auth module in OpenAM before 14.6.6 allows a "replace Samba username attack."
- CVE-2014-7246Nov 14, 2014risk 0.00cvss —epss 0.01
The Core Server in OpenAM 9.5.3 through 9.5.5, 10.0.0 through 10.0.2, 10.1.0-Xpress, and 11.0.0 through 11.0.2, when deployed on a multi-server network, allows remote authenticated users to cause a denial of service (infinite loop) via a crafted cookie in a request.