VYPR
Vendor

OpenAM Consortium

Products
5
CVEs
7
Across products
8
Status
Private

Products

5

Recent CVEs

7
  • CVE-2023-22320HigJan 10, 2023
    risk 0.49cvss 7.5epss 0.01

    OpenAM Web Policy Agent (OpenAM Consortium Edition) provided by OpenAM Consortium parses URLs improperly, leading to a path traversal vulnerability(CWE-22). Furthermore, a crafted URL may be evaluated incorrectly.

  • CVE-2018-0696HigFeb 13, 2019
    risk 0.49cvss 7.5epss 0.01

    OpenAM (Open Source Edition) 13.0 and later does not properly manage sessions, which allows remote authenticated attackers to change the security questions and reset the login password via unspecified vectors.

  • CVE-2026-46560higJun 25, 2026
    risk 0.45cvss —epss —

    ## Summary **Description** An Improper Verification of Cryptographic Signature (CWE-347) issue in OpenAM's RADIUS authentication module allows an unauthenticated network attacker to spoof an Access-Accept response and obtain an OpenAM session for any RADIUS username, without…

  • CVE-2022-31735MedSep 15, 2022
    risk 0.40cvss 6.1epss 0.01

    OpenAM Consortium Edition version 14.0.0 provided by OpenAM Consortium contains an open redirect vulnerability (CWE-601). When accessing an affected server through some specially crafted URL, the user may be redirected to an arbitrary website.

  • CVE-2025-8662MedSep 2, 2025
    risk 0.28cvss 4.3epss 0.00

    OpenAM (OpenAM Consortium Edition) contains a vulnerability that may cause it to malfunction as a SAML IdP due to a tampered request.This issue affects OpenAM: from 14.0.0 through 14.0.1.

  • CVE-2022-34298MedJun 23, 2022
    risk 0.28cvss 5.3epss 0.03

    The NT auth module in OpenAM before 14.6.6 allows a "replace Samba username attack."

  • CVE-2014-7246Nov 14, 2014
    risk 0.00cvss —epss 0.01

    The Core Server in OpenAM 9.5.3 through 9.5.5, 10.0.0 through 10.0.2, 10.1.0-Xpress, and 11.0.0 through 11.0.2, when deployed on a multi-server network, allows remote authenticated users to cause a denial of service (infinite loop) via a crafted cookie in a request.