PT-2026-104579 · Forgerock · Openam
CVSS v3.1
4.7
Medium
| Vector | AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
OpenAM versions prior to 16.1.3
Description
An open redirect issue exists where unauthenticated attackers can redirect users by providing an unverified
id token hint to the '/oauth2/connect/endSession' endpoint. By specifying any realm client in a forged hint, attackers can redirect victims to any registered post-logout URI, which can be used to facilitate phishing attacks by leveraging the trust associated with the OpenAM host.Recommendations
Update to version 16.1.3 or later.
As a temporary mitigation, restrict access to the '/oauth2/connect/endSession' endpoint or avoid using the
id token hint parameter until the update is applied.Fix
Improper Verification of Cryptographic Signature
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openam