Impact
The vulnerability is an email content injection flaw in OpenAM, classified as CWE‑20, that allows an unauthenticated attacker to supply arbitrary subject and message fields on the forgotPassword and register endpoints exposed at /json/{realm}/users. By controlling these fields, the attacker can send phishing emails or use the service as an email relay, sending mail from the server’s configured From address to arbitrary recipients. This can lead to credential theft, spoofing, and other social‑engineering attacks, compromising the confidentiality and integrity of the organization’s communications.
Affected Systems
The affected product is OpenIdentityPlatform OpenAM. All releases prior to version 16.1.3 are vulnerable, including 16.1.2 and earlier revisions.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, and the probability of exploitation is not quantified (EPSS not available). The vulnerability is not listed in CISA’s KEV catalog. Attackers can exploit the flaw without authentication by sending specially crafted JSON to the mentioned REST endpoints, which are reachable from the network where the OpenAM server is exposed.
OpenCVE Enrichment