org.openidentityplatform.openam:openam-core
Maven4 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting org.openidentityplatform.openam:openam-corepage 1 of 1
- CVE-2022-34298MEDIUMCVSS 5.3EG 5.3✓ Fixed in 14.6.62022-06-23
vulnerable: 14.5.2 ... 14.6.5 (8 versions)
The NT auth module in OpenAM before 14.6.6 allows a "replace Samba username attack."
- CVE-2026-44202MEDIUMEG not assessed✓ Fixed in 16.1.12026-06-22
vulnerable: 14.5.2 ... 16.1.0 (40 versions)
OpenAM Authenticated Server-Side Request Forgery (SSRF) via `/sessionservice` OpenAM (Open Identity Platform) is an open-source Identity and Access Management (IAM) platform derived from ForgeRock OpenAM, providing SSO, OAuth2, SAML, and …
- CVE-2026-45048HIGHCVSS 8.5EG 8.5✓ Fixed in 16.1.12026-06-23
vulnerable: 14.5.2 ... 16.1.0 (40 versions)
OpenAM Authenticated Privilege Escalation via Raw Token Disclosure Session RPC ## Summary Description An insufficient authorization (CWE-285) and information exposure (CWE-200) issue in OpenAM's session management endpoint allows a low-…
- CVE-2026-62379CRITICALCVSS 9.8EG 9.8✓ Fixed in 16.1.22026-07-24
vulnerable: 14.5.2 ... 16.1.1 (41 versions)
OpenAM: Unauthenticated Remote Code Execution via Class.forName in AuthXMLUtils.createCustomCallback ## Summary A pre-authentication remote code execution vulnerability affects OpenAM. The remote authentication endpoint (`/authservice`, P…
Check whether org.openidentityplatform.openam:openam-core is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for org.openidentityplatform.openam:openam-core CVEs against the assets you own.
Start Free Scan →