Osstech's vulnerability footprint centers on OpenAM, an identity and access management platform that provides authentication and single sign-on services, with observed weaknesses clustering around open redirects, improper authentication mechanisms, and weak password recovery implementations. These recurrent flaws reflect the authentication and trust-boundary handling demands of identity platforms; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Osstech over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-0696HIGH OpenAM (Open Source Edition) 13.0 and later does not properly manage sessions, which allows remote authenticated attackers to change the security questions and reset the login pass | Feb 13, 2019 | 7.5 | 25 | NO | NO |
CVE-2022-31735MEDIUM OpenAM Consortium Edition version 14.0.0 provided by OpenAM Consortium contains an open redirect vulnerability (CWE-601). When accessing an affected server through some specially c | Sep 15, 2022 | 6.1 | 21 | NO | NO |
CVE-2019-5915MEDIUM Open redirect vulnerability in OpenAM (Open Source Edition) 13.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a specially craft | Feb 13, 2019 | 6.1 | 21 | NO | NO |
CVE-2017-10873HIGH OpenAM (Open Source Edition) allows an attacker to bypass authentication and access unauthorized contents via unspecified vectors. Note that this vulnerability affects OpenAM (Open | Nov 2, 2017 | 8.1 | 21 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Osstech.
Media articles that mention a CVE ID that affects a product developed by Osstech — matched by CVE ID, not by vendor name.