Impact
A flaw in OpenAM before version 16.1.1 allows an unauthenticated attacker to craft a URL that causes the server to render user‑supplied parameters inconsistent with encoding rules in the SAML2 cluster cookie‑hash redirect path. When a victim follows the crafted link, arbitrary JavaScript is executed in the OpenAM origin, giving the attacker the ability to run scripts in the user’s browser. The weakness is a classic reflected XSS (CWE‑79) and, according to the description, results only in script execution, not additional privileges or services.
Affected Systems
OpenIdentityPlatform's OpenAM product is vulnerable when a non‑default clustered configuration is used in any release prior to 16.1.1. The fix was included in the 16.1.1 release; all installations older than that version that use the affected federation endpoints remain at risk.
Risk and Exploitability
The CVSS score of 7 indicates high severity. The EPSS score is below 1 %, implying that exploitation is considered unlikely, and the vulnerability does not appear in the CISA KEV catalog. The attack requires the victim to be directed to a malicious URL and to click it; the attacker does not need credentials but can inject code that runs in the victim’s browser.
OpenCVE Enrichment
Github GHSA