PT-2026-104581 · Forgerock · Openam
CVSS v3.1
4.9
Medium
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
OpenAM versions prior to 16.1.3
Description
An authorization bypass exists in the sessions REST endpoint query operation. This issue allows users with delegated RealmAdmin privileges to list sessions across different realms by supplying a
queryFilter that specifies another realm. This can lead to the disclosure of usernames, universal IDs, and session handles across tenant boundaries.Recommendations
Update to version 16.1.3 or later.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openam