PT-2026-104575 · Forgerock · Openam
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
OpenAM versions prior to 16.1.3
Description
An issue exists where unauthenticated attackers can perform reflected cross-site scripting (XSS) by providing crafted parameters that are rendered without proper encoding on the OAuth2 authorization error page. By luring victims to a malicious
/oauth2/authorize endpoint, attackers can execute JavaScript within the OpenAM origin to operate within existing sessions or redirect users to phishing pages.Recommendations
Update to version 16.1.3 or later.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openam