Impact
The vulnerability lies in the /sessionservice addSessionListener operation, which allows any authenticated user to register an arbitrary notification URL without requiring administrative or application client privileges. The OpenAM server then forwards the attacker‑controlled destination to the session listener service, causing outbound requests that can leak session‑related data to a Server‑Side Request Forgery (SSRF) and maps to CWE‑918. It does not lead to code execution but can expose sensitive information to external sites.
Affected Systems
This flaw affects any OpenIdentityPlatform OpenAM deployment running a version prior to 16.1.1. All installations of OpenAM 16.0.x and earlier that expose the /sessionservice endpoint to normal users are vulnerable. The fix was released in version 16.1.1 and later.
Risk and Exploitability
The CVSS score of 5.3 reflects moderate impact, while the EPSS score is less than 1 %, indicating a low probability of exploitation at present. The vulnerability is not listed in CISA’s KEV catalog. An attacker must first authenticate to OpenAM and then invoke the addSessionListener endpoint with a malicious URL. The server will make an outbound request to that URL, potentially leaking session data to the attacker’s controlled destination. No elevated privileges are required, so any authenticated user with access to the endpoint can exploit the flaw.
OpenCVE Enrichment
Github GHSA