Impact
The vulnerability is a reflected Cross‑Site Scripting flaw in OpenAM's OAuth 2.0 and OpenID Connect authorization endpoint when the form_post response mode is used. Prior to version 16.1.1 the service fails to properly encode user‑supplied parameters such as the state value before rendering the form in FormPostResponse.ftl and checkSession.ftl. An unauthenticated attacker can craft a malicious OAuth request, prompt a victim to visit it, and have script executed in the victim’s browser within the OpenAM origin. The flaw does not affect the server side; the impact consists of client‑side code execution in the victim’s context.
Affected Systems
OpenIdentityPlatform OpenAM versions prior to 16.1.1 are affected; all deployments using the OAuth2/OIDC authorization endpoint with form_post response mode are at risk.
Risk and Exploitability
The CVSS base score of 8.3 indicates high severity; the EPSS score of less than 1% suggests low exploitation probability; the vulnerability is not listed in the CISA KEV catalog; the exploit requires an unauthenticated user to be tricked into opening a malicious OAuth request, so it is a remote client‑side XSS that is easy to construct but needs phishing or social engineering.
OpenCVE Enrichment
Github GHSA