org.openidentityplatform.openam:openam-federation-library
Maven3 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting org.openidentityplatform.openam:openam-federation-librarypage 1 of 1
- CVE-2023-37471CRITICALCVSS 9.1EG 9.1✓ Fixed in 14.7.32023-07-20
vulnerable: 14.5.2 ... 14.7.2 (12 versions)
Open Access Management (OpenAM) is an access management solution that includes Authentication, SSO, Authorization, Federation, Entitlements and Web Services Security. OpenAM up to version 14.7.2 does not properly validate the signature of …
- CVE-2026-44793HIGHCVSS 7.0EG 7.0✓ Fixed in 16.1.12026-06-22
vulnerable: 14.5.2 ... 16.1.0 (40 versions)
Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, certain federation endpoints in a non-default clustered configuration inconsistently encode user-supplied parameters rendered into HTML in the SAML2 cluster…
- CVE-2026-45052CRITICALCVSS 9.3EG 9.3✓ Fixed in 16.1.12026-06-24
vulnerable: 14.5.2 ... 16.1.0 (40 versions)
Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the Liberty Web Services SOAP receiver permits unauthenticated remote requests to write persistent entries through SOAPReceiver and DiscoveryService into a …
Check whether org.openidentityplatform.openam:openam-federation-library is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for org.openidentityplatform.openam:openam-federation-library CVEs against the assets you own.
Start Free Scan →