VYPR
Vendor

Openidentityplatform

Products
2
CVEs
16
Across products
16
Status
Private

Products

2

Recent CVEs

16
  • CVE-2026-33439CriApr 7, 2026
    risk 0.57cvss 9.8epss 0.08

    Open Access Management (OpenAM) is an access management solution. Prior to 16.0.6, OpenIdentityPlatform OpenAM is vulnerable to pre-authentication Remote Code Execution (RCE) via unsafe Java deserialization of the jato.clientSession HTTP parameter. This bypasses the…

  • CVE-2026-73644CriAug 13, 2026
    risk 0.55cvss 9.6epss 0.00

    OpenDJ is an LDAPv3 compliant directory service. Prior to 5.1.2, the SASL PLAIN authorization identity path in opendj-server-legacy/src/main/java/org/opends/server/extensions/PlainSASLMechanismHandler.java checked the PROXIED_AUTH privilege but did not evaluate the mayProxy…

  • CVE-2026-46619CriSep 15, 2026
    risk 0.54cvss —epss 0.01

    Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, MSISDNValidation in the MSISDN authentication module concatenates the request-supplied MSISDN value into an LDAP search filter without escaping, while the default empty trusted-gateway list allows…

  • CVE-2026-46495CriSep 15, 2026
    risk 0.53cvss —epss 0.01

    OpenDJ is an LDAPv3 compliant directory service. Prior to 5.1.1, the JMX RMI connector in opendj-server-legacy/src/main/java/org/opends/server/protocols/jmx/RmiConnector.java processes attacker-controlled credential objects before authentication without a restrictive…

  • CVE-2026-48717CriSep 15, 2026
    risk 0.52cvss —epss 0.01

    Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, AuthorizationCodeGrantTypeHandler requires a code_verifier only when the realm-wide codeVerifierEnforced setting is enabled, even when an authorization code stores a code_challenge. Because that…

  • CVE-2023-37471CriJul 20, 2023
    risk 0.52cvss 9.1epss 0.01

    Open Access Management (OpenAM) is an access management solution that includes Authentication, SSO, Authorization, Federation, Entitlements and Web Services Security. OpenAM up to version 14.7.2 does not properly validate the signature of SAML responses received as part of the…

  • CVE-2025-27497HigMar 5, 2025
    risk 0.50cvss —epss 0.00

    OpenDJ is an LDAPv3 compliant directory service. OpenDJ prior to 4.9.3 contains a denial-of-service (DoS) vulnerability that causes the server to become unresponsive to all LDAP requests without crashing or restarting. This issue occurs when an alias loop exists in the LDAP…

  • CVE-2024-41667HigJul 24, 2024
    risk 0.50cvss 8.8epss 0.04

    OpenAM is an open access management solution. In versions 15.0.3 and prior, the `getCustomLoginUrlTemplate` method in RealmOAuth2ProviderSettings.java is vulnerable to template injection due to its usage of user input. Although the developer intended to implement a custom URL…

  • CVE-2026-45048HigSep 15, 2026
    risk 0.48cvss 8.5epss 0.00

    Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, SessionRequestHandler in the session management endpoint does not enforce ownership or privilege checks when a low-privileged authenticated user queries session information in deployments using…

  • CVE-2026-45794HigSep 15, 2026
    risk 0.43cvss —epss 0.01

    Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the anonymous Push Notification SNS callback handled by SnsMessageResource falls back to a CTS predicate blob after a messageId expires from the in-memory dispatcher, treats top-level blob keys as…

  • CVE-2026-47426HigSep 15, 2026
    risk 0.42cvss —epss 0.01

    Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the private_key_jwt client authentication path uses ClientJwksResolverCache without reliably binding a cached jwks_uri resolver and verified assertion to the expected clientID in…

  • CVE-2026-47424HigSep 15, 2026
    risk 0.42cvss —epss 0.00

    Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, GroovySandboxValueFilter permits an authenticated server-side script author to escape the scripting sandbox despite the default class allow and deny lists. A user such as a sub-realm RealmAdmin…

  • CVE-2026-46498HigSep 15, 2026
    risk 0.42cvss —epss 0.00

    Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, OAuthTokenStore reads caller-supplied token identifiers from the shared Core Token Store (CTS) without an OAuth-only namespace, and OAuthAdapter accepts a row whose BLOB claims to contain an OAuth…

  • CVE-2026-46623HigSep 15, 2026
    risk 0.41cvss —epss 0.01

    Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the OAuth2 authentication module updates an existing local account with profile attributes that can include userPassword and inetUserStatus, rewriting the password to the username and reactivating…

  • CVE-2026-62280MedSep 15, 2026
    risk 0.33cvss 6.1epss 0.00

    Open Access Management (OpenAM) is an access management solution. From 13.0.0 until 16.1.2, the OAuth2 authorize endpoint's display=wap consent page reflects request-derived values through ConsentRequiredResource and wap/authorize.ftl without HTML escaping. An attacker can…

  • CVE-2022-34298MedJun 23, 2022
    risk 0.28cvss 5.3epss 0.03

    The NT auth module in OpenAM before 14.6.6 allows a "replace Samba username attack."