PT-2022-20899 · Unknown · Openam Consortium Edition

·

CVE-2022-31735

·

Published

2022-09-15

·

Updated

2022-09-19

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions OpenAM Consortium Edition version 14.0.0
Description The issue allows an open redirect when accessing an affected server through a specially crafted URL, potentially redirecting the user to an arbitrary website.
Recommendations For OpenAM Consortium Edition version 14.0.0, consider restricting access to specially crafted URLs to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Open Redirect

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-31735

Affected Products

Openam Consortium Edition