OpenIdentityPlatform OpenAM
27 known vulnerabilities in OpenIdentityPlatform OpenAM, 6 critical, with patch priority, exploit likelihood and the news covering them.
Latest vulnerabilities
- CVE-2026-105122 CVSS 5.3 medium OpenAM before 16.1.3 contains a server-side request forgery vulnerability that allows attackers able to register or modify OAuth 2.0…
- CVE-2026-105121 CVSS 6.9 medium OpenAM before 16.1.3 contains an improper authorization vulnerability that allows delegated administrators to destroy sessions outside…
- CVE-2026-105120 CVSS 6.9 medium OpenAM before 16.1.3 contains an authorization bypass vulnerability in the sessions REST endpoint query operation that allows realm…
- CVE-2026-105119 CVSS 7.6 high OpenAM before 16.1.3 applies its OAuth2 Provider PKCE enforcement only to authorization requests whose response_type is exactly code, so…
- CVE-2026-105118 CVSS 2.3 low OpenAM before 16.1.3 contains an open redirect vulnerability that allows unauthenticated attackers to redirect users by supplying an…
- CVE-2026-105117 CVSS 5.3 medium OpenAM before 16.1.3 contains an email content injection vulnerability that allows unauthenticated attackers to control notification email…
- CVE-2026-105116 CVSS 5.1 medium OpenAM before 16.1.3 contains a latent cross-site scripting defect that places the SAML message, relay state and target URL unencoded into…
- CVE-2026-105115 CVSS 8.8 high OpenAM before 16.1.3 contains an unauthenticated arbitrary class instantiation vulnerability in the legacy JAX-RPC SOAP interface that…
- CVE-2026-105114 CVSS 5.3 medium OpenAM before 16.1.3 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject script by…
- CVE-2026-62379 CVSS 9.8 critical Open Access Management (OpenAM) is an access management solution. Prior to 16.1.2, the pre-authentication /authservice PLL endpoint…
- CVE-2026-62280 CVSS 6.1 medium Open Access Management (OpenAM) is an access management solution. From 13.0.0 until 16.1.2, the OAuth2 authorize endpoint's display=wap…
- CVE-2026-62263 CVSS 9.2 critical Open Access Management (OpenAM) is an access management solution. Prior to 16.1.2, WebAuthnAuthentication.deserialize applies an…
- CVE-2026-53660 CVSS 7.4 high Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the default configuration initializes the…
- CVE-2026-48717 CVSS 9.1 critical Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, AuthorizationCodeGrantTypeHandler requires a…
- CVE-2026-47426 CVSS 7.6 high Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the private_key_jwt client authentication path uses…
- CVE-2026-47424 CVSS 7.5 high Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, GroovySandboxValueFilter permits an authenticated…
- CVE-2026-46623 CVSS 7.4 high Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the OAuth2 authentication module updates an existing…
- CVE-2026-46619 CVSS 9.3 critical Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, MSISDNValidation in the MSISDN authentication module…
- CVE-2026-46498 CVSS 7.6 high Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, OAuthTokenStore reads caller-supplied token identifiers…
- CVE-2026-45794 CVSS 7.7 high Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the anonymous Push Notification SNS callback handled by…
- CVE-2026-45052 CVSS 9.3 critical Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the Liberty Web Services SOAP receiver permits…
- CVE-2026-45051 CVSS 9.2 critical Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, WebAuthnAuthentication loads a serialized…
- CVE-2026-45048 CVSS 8.5 high Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, SessionRequestHandler in the session management…
- CVE-2026-44793 CVSS 7.0 high Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, certain federation endpoints in a non-default clustered…
- CVE-2026-44203 CVSS 8.3 high Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the OAuth 2.0 and OpenID Connect authorization endpoint…
- CVE-2026-44202 CVSS 5.3 medium Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the /sessionservice addSessionListener operation allows…
- CVE-2026-41573 CVSS 7.1 high Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, IdentityResourceV1.queryCollection() passes the…