Impact
OpenAM users exposed the possibility for an attacker with valid authentication to inject LDAP metacharacters by exploiting the unescaped _queryId parameter in the /json/{realm}/users endpoint. Prior to version 16.1.1, the IdentityResourceV1.queryCollection() method forwarded this value to CrestQuery with escapeQueryId disabled, bypassing earlier defenses for CVE-2021-29156. The unescaped value reached DJLDAPv3Repo.getFilter(), where it was concatenated into an LDAP filter, allowing user enumeration and blind LDAP injection. This flaw was identified as CWE‑90 and carries a CVSS score of 7.1, indicating a high severity impact on data confidentiality and potential privilege escalation.
Affected Systems
All OpenIdentityPlatform OpenAM installations running any version before 16.1.1 are affected. The fix is implemented in OpenAM release 16.1.1 and later versions.
Risk and Exploitability
The risk is high but the probability of exploitation remains low, with an EPSS score of less than 1%. The CVSS score of 7.1 reflects a high severity. Not listed in the CISA KEV catalog. Attacks would require authenticated access to the affected endpoint and the ability to manipulate the _queryId parameter, so the threat is primarily to authenticated users who can enumerate credentials or perform further LDAP queries.
OpenCVE Enrichment
Github GHSA