OpenAM: Unauthenticated Remote Code Execution via Class.forName in AuthXMLUtils.createCustomCallback
Summary
A pre-authentication remote code execution vulnerability affects OpenAM. The remote authentication endpoint (/authservice, PLL) accepts an XML element
that names an arbitrary Java class, which the server then loads and
instantiates without validation. On a default configuration this is reachable
without authentication and allows an attacker to run code on the server.Impact
Unauthenticated remote code execution / full server compromise on any OpenAM instance with default settings.Affected
All releases up to and including 16.1.1 (the defect predates the Open Identity Platform fork).Remediation
Upgrade to16.1.2.Interim mitigation
- Require the remote-auth security token by enabling
sunRemoteAuthSecurityEnabled (rejects unauthenticated /authservice calls).
- Restrict or block external network access to
/authserviceuntil patched.