No analysis available yet.
Vendor Solution
The OpenAM Consortium has released OpenAM 14.0.2, which addresses the vulnerability. Please update to the released OpenAM version.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-26407 | OpenAM (OpenAM Consortium Edition) contains a vulnerability that may cause it to malfunction as a SAML IdP due to a tampered request.This issue affects OpenAM: from 14.0.0 through 14.0.1. |
| Link | Providers |
|---|---|
| https://openam-jp.github.io/Advisories/CVE-2025-8662/ |
|
Thu, 04 Sep 2025 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:openam:openam:*:*:*:*:consortium:*:*:* | |
| Metrics |
cvssV3_1
|
Wed, 03 Sep 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-20 |
Tue, 02 Sep 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 02 Sep 2025 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Openam
Openam openam |
|
| Vendors & Products |
Openam
Openam openam |
Tue, 02 Sep 2025 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OpenAM (OpenAM Consortium Edition) contains a vulnerability that may cause it to malfunction as a SAML IdP due to a tampered request.This issue affects OpenAM: from 14.0.0 through 14.0.1. | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: openam-jp
Published:
Updated: 2025-09-03T14:36:15.486Z
Reserved: 2025-08-06T07:06:29.261Z
Link: CVE-2025-8662
Updated: 2025-09-02T16:05:20.674Z
Status : Analyzed
Published: 2025-09-02T03:15:42.747
Modified: 2025-09-04T16:56:19.207
Link: CVE-2025-8662
No data.
OpenCVE Enrichment
Updated: 2025-09-02T15:23:05Z
EUVD