Impact
The vulnerability is an insecure deserialization flaw (CWE-502) that allows an unauthenticated attacker to inject a malicious serialized Java object via the jato.clientSession HTTP parameter. The flaw exists in OpenIdentityPlatform OpenAM versions prior to 16.0.6 and bypasses a mitigation that was applied to the jato.pageSession parameter after a previous CVE, giving the attacker the ability to execute arbitrary system commands on the server. Because the flaw is encountered before any authentication step, the target becomes an untrusted endpoint that can run any code supplied by the attacker, compromising confidentiality, integrity, and availability of the host system.
Affected Systems
OpenIdentityPlatform OpenAM versions earlier than 16.0.6 are affected. Any JATO ViewBean endpoint whose JSP contains <jato:form> tags, such as Password Reset pages, receives the vulnerable jato.clientSession parameter and is thus at risk. The flaw is present in the handling of this parameter before user authentication.
Risk and Exploitability
The CVSS score of 9.3 indicates a critical severity. The EPSS score of 8% indicates a moderate exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is an unauthenticated attacker sending a crafted serialized Java object as the jato.clientSession GET/POST parameter to any vulnerable endpoint, achieving remote code execution.
OpenCVE Enrichment
Github GHSA