Impact
The flaw is an improper authorization vulnerability in the session-destroy endpoint of OpenAM. Delegated administrators that possess the iplanet-am-session-destroy-sessions attribute can supply a session identifier or handle and forcefully log out any user, regardless of the realm that owns the session. This capability enables the attacker to disrupt service availability and undermine accountability across all realms. The weakness is classified as CWE‑285.
Affected Systems
Products from OpenIdentityPlatform, specifically OpenAM versions prior to 16.1.3, are affected. Those installations perform realm checks using the requester's realm instead of the target session’s realm, which allows the described privilege escalation.
Risk and Exploitability
The CVSS score of 6.9 indicates a medium severity. With the EPSS score not available and no listing in the CISA KEV catalog, the likelihood of widespread exploitation appears moderate to low; however, the ability to terminate arbitrary sessions could be leveraged in targeted assaults. The attack vector is inferred to be remote via the network: an attacker first authenticates as a delegated admin with the required attribute, then submits a request to the session-destroy endpoint to exploit the flaw.
OpenCVE Enrichment