CVE-2023-37471
CRITICALOpenidentityplatform Openam < 14.7.3 - Authentication Bypass
Title source: ruleDescription
Open Access Management (OpenAM) is an access management solution that includes Authentication, SSO, Authorization, Federation, Entitlements and Web Services Security. OpenAM up to version 14.7.2 does not properly validate the signature of SAML responses received as part of the SAMLv1.x Single Sign-On process. Attackers can use this fact to impersonate any OpenAM user, including the administrator, by sending a specially crafted SAML response to the SAMLPOSTProfileServlet servlet. This problem has been patched in OpenAM 14.7.3-SNAPSHOT and later. User unable to upgrade should comment servlet `SAMLPOSTProfileServlet` from their pom file. See the linked GHSA for details.
References (3)
Core 3
Core References
Vendor Advisory x_refsource_confirm
https://github.com/OpenIdentityPlatform/OpenAM/security/advisories/GHSA-4mh8-9wq6-rjxg
Patch x_refsource_misc
https://github.com/OpenIdentityPlatform/OpenAM/pull/624
Scores
CVSS v3
9.1
EPSS
0.0161
EPSS Percentile
81.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
total
Details
CWE
CWE-287
Status
published
Products (2)
openidentityplatform/openam
< 14.7.3
org.openidentityplatform.openam/openam-federation-library
0 - 14.7.3Maven
Published
Jul 20, 2023
Tracked Since
Feb 18, 2026