CyberRota Analysis
AI-GeneratedOpenAM prior to version 16.1.1 is vulnerable due to inconsistent encoding of user-supplied parameters in certain federation endpoints within non-default clustered configurations. This flaw allows unauthenticated attackers to craft requests that can execute scripts in the OpenAM origin, potentially leading to cross-site scripting (XSS) attacks. Organizations using OpenAM in clustered environments should prioritize applying the update to mitigate the risk of exploitation.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, certain federation endpoints in a non-default clustered configuration inconsistently encode user-supplied parameters rendered into HTML in the SAML2 cluster cookie-hash redirect path. An unauthenticated attacker can induce a user to follow a crafted request and execute script in the OpenAM origin. This issue is fixed in version 16.1.1.