org.openidentityplatform.openam:openam-core
Maven5 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting org.openidentityplatform.openam:openam-corepage 1 of 1
- CVE-2022-34298MEDIUMCVSS 5.3EG 5.3✓ Fixed in 14.6.62022-06-23
vulnerable: 14.5.2 ... 14.6.5 (8 versions)
The NT auth module in OpenAM before 14.6.6 allows a "replace Samba username attack."
- CVE-2026-44202MEDIUMCVSS 5.3EG 5.3✓ Fixed in 16.1.12026-06-22
vulnerable: 14.5.2 ... 16.1.0 (40 versions)
Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the /sessionservice addSessionListener operation allows an authenticated user to register an arbitrary notification URL without requiring an administrative …
- CVE-2026-45048HIGHCVSS 8.5EG 8.5✓ Fixed in 16.1.12026-06-23
vulnerable: 14.5.2 ... 16.1.0 (40 versions)
Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, SessionRequestHandler in the session management endpoint does not enforce ownership or privilege checks when a low-privileged authenticated user queries ses…
- CVE-2026-53660HIGHCVSS 7.4EG 7.4✓ Fixed in 16.1.12026-08-14
vulnerable: 14.5.2 ... 16.1.0 (40 versions)
Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the default configuration initializes the iPlanetDirectoryPro SSO cookie with HttpOnly disabled and without a protective SameSite default, and OAuth and Ope…
- CVE-2026-62379CRITICALCVSS 9.8EG 9.8✓ Fixed in 16.1.22026-07-24
vulnerable: 14.5.2 ... 16.1.1 (41 versions)
Open Access Management (OpenAM) is an access management solution. Prior to 16.1.2, the pre-authentication /authservice PLL endpoint accepts a CustomCallback XML element whose className value selects an arbitrary Java class for AuthXMLUtils…
Check whether org.openidentityplatform.openam:openam-core is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for org.openidentityplatform.openam:openam-core CVEs against the assets you own.
Start Free Scan →