Impact
OpenAM versions before 16.1.3 contain an authorization bypass in the sessions REST endpoint that lets a user with RealmAdmin privileges query the sessions of any realm. The flaw allows disclosure of usernames, universal IDs, and session handles spanning across tenant boundaries. This information breach compromises confidentiality and could enable further session hijacking or credential misuse. The weakness is an authorization flaw classified as CWE-200.
Affected Systems
Vendors and products affected are the OpenIdentityPlatform OpenAM solutions prior to version 16.1.3. Any installation of OpenAM running an earlier major release that exposes the sessions REST API is potentially vulnerable. The vulnerability applies to the default REST endpoint in these releases.
Risk and Exploitability
The CVSS score is 6.9, indicating a moderate severity. EPSS score is currently unavailable, so the likelihood of exploitation is unknown, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires the attacker to possess delegated RealmAdmin privileges and to access the REST API over the network, which is typically provided via HTTPS. The attacker can inject a _queryFilter with a target realm name to retrieve session data from other realms.
OpenCVE Enrichment