Impact
OpenAM versions before 16.1.3 contain a latent cross‑site scripting defect that places the SAML message, relay state and target URL without encoding into the load‑balancer cookie bounce auto‑submit page. If an attacker can reach the page when the cookieHashRedirectEnabled option is turned on, crafted requests could cause script execution in the OpenAM origin domain. However, a separate HTTP 500 failure in released releases stops the code from running, so the flaw has not been successfully exploited yet.
Affected Systems
The vulnerability affects OpenIdentityPlatform’s OpenAM product in all versions prior to 16.1.3. No other products or versions are listed as impacted.
Risk and Exploitability
The CVSS score of 5.1 indicates a medium impact. The EPSS score is not available and the flaw is not present in the CISA KEV catalog, so the likelihood of widespread exploitation is low at present. The flaw can be triggered only if cookieHashRedirectEnabled is enabled and the attacker can create a crafted request to the bounce page, making exploitation scenarios relatively constrained.
OpenCVE Enrichment