PT-2026-104577 · Forgerock · Openam
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
OpenAM versions prior to 16.1.3
Description
A cross-site scripting defect exists where the SAML message, relay state, and target URL are placed unencoded into the load-balancer cookie bounce auto-submit page. This issue is reachable when
cookieHashRedirectEnabled is set, potentially allowing script execution in the OpenAM origin. However, an unrelated HTTP 500 failure prevents exploitation in released versions.Recommendations
Update to version 16.1.3 or later.
As a temporary mitigation, ensure the
cookieHashRedirectEnabled setting is disabled.Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openam