Impact
OpenAM before version 16.1.3 has a flaw that allows attackers who are not authenticated to trigger a redirect by supplying an unverified id_token_hint to the /oauth2/connect/endSession endpoint. Because the supplied token hint is not validated, the system will redirect the user to a post‑logout URI that was registered for the specified realm. An attacker can choose any realm and any registered redirect target, effectively causing the victim to be sent to a malicious site that can be used for phishing or credential theft.
Affected Systems
The affected products are OpenIdentityPlatform OpenAM, all releases prior to 16.1.3. The vulnerability applies to any installation that accepts unverified id_token_hint values for the endSession endpoint. Specific versions are not listed beyond the 16.1.3 cutoff, so all older builds that have not applied subsequent patches are potentially vulnerable.
Risk and Exploitability
The CVSS score of 2.3 reflects a low impact in terms of attacker's privileges, but the exploit is trivial to execute: an unauthenticated user only needs to send a crafted /endSession request with a forged id_token_hint. Because the redirect target is controlled by the attacker, there is no requirement for privileged access, and the risk of phishing and social engineering is amplified by the OpenAM host’s reputation. EPSS data is not available and the vulnerability is not currently listed in the CISA KEV catalog, indicating that while widespread exploitation is not known, the potential for abuse remains.
OpenCVE Enrichment