Impact
OpenAM before version 16.1.3 allows an attacker to trigger arbitrary class instantiation by sending specially crafted SOAP requests to the legacy JAX‑RPC interface. The vulnerability is a misuse of the class loader that does not enforce authentication, enabling an attacker to load electively chosen classes without credentials. The impact ranges from server crashes and class‑path enumeration to potential code execution if vulnerable gadget chains are present. The weakness is categorized as CWE‑306, reflecting an insecure fallback to unauthenticated access.
Affected Systems
The affected product is OpenIdentityPlatform’s OpenAM, all releases prior to 16.1.3. No specific sub‑product version information was provided beyond the overall product name, but any deployment of OpenAM that has not applied the 16.1.3 patch may be vulnerable.
Risk and Exploitability
The CVSS score of 8.8 indicates a high‑severity vulnerability with the potential for remote exploitation. The EPSS score is not available, so the real‑world exploitation probability cannot be quantified, and the vulnerability is not currently listed in the CISA KEV catalog. Attackers would need to compose a valid SOAP request targeting the /jaxrpc/* endpoint and provide an unverified session identifier; if successful, the server could be coerced into loading arbitrary classes, leading to crashes, inventory gathering, or, with suitable gadget chains, arbitrary code execution. The lack of authentication and the remote nature of the flaw make this an attractive target for automated attackers.
OpenCVE Enrichment