PT-2026-104582 · Forgerock · Openam
CVSS v3.1
4.9
Medium
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
OpenAM versions prior to 16.1.3
Description
An improper authorization issue exists where delegated administrators can destroy sessions outside their assigned realms. This occurs because realm checks are performed using the requester's realm rather than the target session's realm. Authenticated accounts possessing the
iplanet-am-session-destroy-sessions attribute can provide a target session identifier or handle to forcibly log out users across any realm.Recommendations
Update to version 16.1.3 or later.
Fix
Improper Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openam