Impact
OpenAM before version 16.1.3 contains an SSRF flaw that allows an attacker who can register or modify OAuth 2.0 clients to force the server to fetch arbitrary resources via an unvalidated jwks_uri. The vulnerability is exploitable during client‑authentication and ID‑token validation, enabling the attacker to probe internal hosts, metadata endpoints, local files, or exhaust request threads, potentially exposing internal information or causing denial of service. The likely attack vector is the OAuth client registration or modification flow, as the description indicates attackers can trigger unauthenticated fetches through these operations.
Affected Systems
The affected product is OpenIdentityPlatform OpenAM. All releases prior to version 16.1.3 are vulnerable; no releases beyond 16.1.3 are known to be affected.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate risk. Because an EPSS score is not available and the vulnerability is not listed in CISA KEV, there is no publicly documented exploitation evidence at this time. Based on the description, it is inferred that an attacker with the ability to register or modify OAuth clients can trigger unauthenticated internal requests or cause service disruption, which suggests that the exploitation risk could be significant in environments exposing client registration to untrusted users.
OpenCVE Enrichment