OpenAM 漏洞列表
共找到 7 个与 OpenAM 相关的漏洞
📅 加载漏洞趋势中...
-
CVE-2021-29156: LDAP Injection In OpenAM POC
OpenAM contains an LDAP injection vulnerability. When a user tries to reset his password, they are asked to enter username, and then the backend validates whether the user exists or not through an LDAP query. If the user exists, the password reset token is sent to the user's email. Enumeration can allow for full password retrieval. -
CVE-2021-35464: ForgeRock OpenAM <7.0 - Remote Code Execution POC
ForgeRock AM server before 7.0 has a Java deserialization vulnerability in the jato.pageSession parameter on multiple pages. The exploitation does not require authentication, and remote code execution can be triggered by sending a single crafted /ccversion/* request to the server. The vulnerability exists due to the usage of Sun ONE Application Framework (JATO) found in versions of Java 8 or earlier. -
CVE-2024-41667: OpenAM<=15.0.3 FreeMarker - Template Injection POC
OpenAM is an open access management solution. In versions 15.0.3 and prior, the `getCustomLoginUrlTemplate` method in RealmOAuth2ProviderSettings.java is vulnerable to template injection due to its usage of user input -
CVE-2021-29156: LDAP Injection In OpenAM POC
OpenAM contains an LDAP injection vulnerability. When a user tries to reset his password, they are asked to enter username, and then the backend validates whether the user exists or not through an LDAP query. If the user exists, the password reset token is sent to the user's email. Enumeration can allow for full password retrieval. -
CVE-2021-35464: ForgeRock OpenAM <7.0 - Remote Code Execution POC
ForgeRock AM server before 7.0 has a Java deserialization vulnerability in the jato.pageSession parameter on multiple pages. The exploitation does not require authentication, and remote code execution can be triggered by sending a single crafted /ccversion/* request to the server. The vulnerability exists due to the usage of Sun ONE Application Framework (JATO) found in versions of Java 8 or earlier. -
CVE-2024-41667: OpenAM<=15.0.3 FreeMarker - Template Injection POC
OpenAM is an open access management solution. In versions 15.0.3 and prior, the `getCustomLoginUrlTemplate` method in RealmOAuth2ProviderSettings.java is vulnerable to template injection due to its usage of user input -
OpenIdentityPlatform OpenAM 需授权 代码注入漏洞 无POC
OpenIdentityPlatform OpenAM 需授权 代码注入漏洞