OpenIdentityPlatform OpenAM versions prior to 16.0.6 contain a critical pre-authentication remote code execution vulnerability stemming from unsafe Java deserialization of the jato.clientSession HTTP parameter. This flaw bypasses previous security mitigations applied to related parameters following CVE-2021-35464, allowing unauthenticated attackers to execute arbitrary commands on affected servers. The vulnerability presents a severe risk profile with a CVSS score of 9.8 (Critical), requiring no authentication, low attack complexity, and no user interaction. An attacker can exploit this vulnerability by sending a malicious serialized Java object to any JATO ViewBean endpoint containing form tags, such as password reset pages, resulting in complete system compromise including confidentiality, integrity, and availability breaches. As of the available data, this vulnerability does not appear to be actively exploited in the wild, with no confirmed presence in the Known Exploited Vulnerabilities (KEV) catalog and minimal community attention indicators. However, given the critical severity rating, ease of exploitation, and network accessibility of typical OpenAM deployments, organizations running affected versions should prioritize immediate patching to version 16.0.6 without awaiting evidence of active exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 16.0.6CPE matchmatch criteria | cpe:2.3:a:openidentityplatform:openam:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.