Impact
OpenAM versions prior to 16.1.3 contain a reflected cross‑site scripting flaw that allows an unauthenticated attacker to inject malicious script into the OAuth2 authorization error page. The vulnerability arises because specially crafted parameters are included in the page without proper encoding. An attacker can lure a user to a malicious \/oauth2\/authorize link that contains repeated parameters, causing arbitrary JavaScript to execute in the victim’s browser under the OpenAM origin. This can be used to manipulate the user’s session or redirect them to phishing sites, potentially leading to credential theft or illicit account takeover.
Affected Systems
OpenIdentityPlatform’s OpenAM product is affected. All deployments running a version earlier than 16.1.3 are susceptible. The vulnerability is present across all platforms that use the default error handling for OAuth2, regardless of underlying operating system or hosting environment.
Risk and Exploitability
The CVSS score is 5.3, indicating medium severity, and the exploit probability is unknown as its EPSS score is unavailable. The vulnerability is not listed in the CISA KEV catalog. An attacker only needs to send a crafted link to a victim; no privileged access is required. The exploit is straightforward, but the impact is limited to the victim’s device, not to the server itself.
OpenCVE Enrichment