Impact
The vulnerability exists in OpenIdentityPlatform OpenAM versions prior to 16.1.1. During the WebAuthn authentication flow, the application deserializes a userAttribute object graph without applying an ObjectInputFilter. An attacker who has already written controlled data into that attribute—through delegated administration, provisioning, directory access, legacy REST self‑registration, unsafe configuration—can inject a malicious Java object that triggers classpath gadget execution before the assertion is verified. The result is arbitrary code execution with the privileges of the application server.
Affected Systems
Affected systems are instances of OpenIdentityPlatform OpenAM running any release older than 16.1.1. The vulnerability is tied to the WebAuthnAuthenticator component and impacts users who can supply data to the configured userAttribute. Administrators deploying1 should check whether their environment allows untrusted writes to that attribute.
Risk and Exploitability
The CVSS score of 9.2 classifies this as a critical flaw, though the EPSS score of less than 1% indicates a very low likelihood of exploitation in the wild, and it is not currently listed in the CISA KEV catalog. Nevertheless, exploitation requires the WebAuthn flow to be exposed and attacker control over the attribute, conditions that are uncommon but possible in misconfigured installations. Given the high severity, the risk remains significant if the prerequisite conditions exist.
OpenCVE Enrichment
Github GHSA