CVEs we hold for Openidentityplatform
Records whose assigning authority named Openidentityplatform as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-73644OpenDJ: Authorization bypass in SASL PLAIN allowing a `proxied-auth` holder to impersonate any resolvable non-root user…OpenIdentityPlatform OpenDJ
CVE-2026-62379OpenAM: Unauthenticated Remote Code Execution via Class.forName in AuthXMLUtils.createCustomCallbackOpenIdentityPlatform OpenAM
CVE-2026-62263OpenAM: WebAuthn Java deserialization RCE via ObjectInputFilter depth>1 bypassOpenIdentityPlatform OpenAM
CVE-2026-46623OpenAM Account Takeover via Unverified Password Change in OAuth2 ModuleOpenIdentityPlatform OpenAM
CVE-2026-46495OpenDJ Pre-Auth RCE via Java Deserialization in JMX RMIOpenIdentityPlatform OpenDJ; org.openidentityplatform.opendj…
CVE-2026-45052OpenAM Pre-auth User Profile Tampering via Anonymous SOAP Authn in Liberty IDPP/Discovery EndpointsOpenIdentityPlatform OpenAM
CVE-2026-45051OpenAM Pre-auth RCE via Java Deserialization in WebAuthn Authenticator StorageOpenIdentityPlatform OpenAM
CVE-2026-45048OpenAM Authenticated Privilege Escalation via Raw Token Disclosure Session RPCOpenIdentityPlatform OpenAM
CVE-2026-44793OpenAM: Pre-authentication Reflected XSS in SAML2 Cluster Cookie-Hash-Redirect Path via `FSUtils.postToTarget`OpenIdentityPlatform OpenAM
CVE-2026-44203OpenAM: Pre-auth Reflected XSS in OAuth2 / OIDC response_mode=form_post via state parameter (FormPostResponse.ftl)OpenIdentityPlatform OpenAM
CVE-2026-44202OpenAM Authenticated Server-Side Request Forgery (SSRF) via `/sessionservice`OpenIdentityPlatform OpenAM
CVE-2026-33439Pre-Authentication Remote Code Execution via `jato.clientSession` Deserialization in OpenAMOpenIdentityPlatform OpenAM
CVE-2025-64099OpenAM allows use of arbitrary OIDC requested claims values in id_token and user_infoOpenIdentityPlatform OpenAM
CVE-2023-37471User impersonation using SAMLv1.x SSO in Open Access ManagementOpenIdentityPlatform OpenAM
25 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.