Impact
An authenticated low‑privileged user can enumerate sessions belonging to other users by querying the SessionRequestHandler endpoint, because the handler does not check that the requester owns the queried session. The attacker may thereby obtain a session token for a higher‑privileged account and hijack that session, effectively gaining the privileges of the target account. This flaw corresponds to inadequate access control and disclosure of sensitive information, as identified by CWE‑200 and CWE‑285.
Affected Systems
OpenIdentityPlatform’s OpenAM product, any deployment using stateful session storage before version 16.1.1. The flaw is fixed in OpenAM 16.1.1.
Risk and Exploitability
The CVSS score of 8.5 classifies the vulnerability as high severity. The very low EPSS score (<1%) suggests that exploitation is considered unlikely at this time, and the vulnerability is not yet documented in the CISA KEV catalog. The attack requires that the adversary already has valid, low‑privileged credentials and can send requests to the session endpoint; once those conditions are met, the vulnerability can be leveraged to hijack a target user’s active session.
OpenCVE Enrichment
Github GHSA