OpenAM (OpenAM Consortium Edition) contains a vulnerability that may cause it to malfunction as a SAML IdP due to a tampered request.This issue affects OpenAM: from 14.0.0 through 14.0.1.
Advisories
Source ID Title
EUVD EUVD EUVD-2025-26407 OpenAM (OpenAM Consortium Edition) contains a vulnerability that may cause it to malfunction as a SAML IdP due to a tampered request.This issue affects OpenAM: from 14.0.0 through 14.0.1.
Fixes

Solution

The OpenAM Consortium has released OpenAM 14.0.2, which addresses the vulnerability. Please update to the released OpenAM version.


Workaround

No workaround given by the vendor.

History

Thu, 04 Sep 2025 18:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:openam:openam:*:*:*:*:consortium:*:*:*
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L'}


Wed, 03 Sep 2025 15:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20

Tue, 02 Sep 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 02 Sep 2025 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Openam
Openam openam
Vendors & Products Openam
Openam openam

Tue, 02 Sep 2025 02:30:00 +0000

Type Values Removed Values Added
Description OpenAM (OpenAM Consortium Edition) contains a vulnerability that may cause it to malfunction as a SAML IdP due to a tampered request.This issue affects OpenAM: from 14.0.0 through 14.0.1.
References
Metrics cvssV4_0

{'score': 2.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: openam-jp

Published:

Updated: 2025-09-03T14:36:15.486Z

Reserved: 2025-08-06T07:06:29.261Z

Link: CVE-2025-8662

cve-icon Vulnrichment

Updated: 2025-09-02T16:05:20.674Z

cve-icon NVD

Status : Analyzed

Published: 2025-09-02T03:15:42.747

Modified: 2025-09-04T16:56:19.207

Link: CVE-2025-8662

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-09-02T15:23:05Z