Impact
A user is affected by an unauthenticated remote vulnerability in OpenAM's Liberty Web Services SOAP receiver before version 16.1.1. The SOAPReceiver and DiscoveryService endpoints allow a remote attacker to issue SOAP requests that write arbitrary persistent entries into both a user’s Liberty Discovery store and the shared root‑realm Discovery branch. Server‑side handlers bypass LDAP and identity ACL checks and rely on an internal administrative token, enabling the attacker to create or modify service‑routing or security‑mechanism records for any user. This manipulation can alter user profiles, service configuration denial of service. This vulnerability is an Improper Authorization flaw (CWE‑285).
Affected Systems
OpenIdentityPlatform OpenAM (prior to version 16.1.1). All deployments consuming Liberty discovery data that expose the SOAPReceiver and DiscoveryService endpoints are vulnerable until the upgrade to 16.1.1 or later, where the issue is fixed.
Risk and Exploitability
The CVSS score of 9.3 marks it as a critical vulnerability with a high potential for attack, while an EPSS score of less than 1% indicates a low current exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Attackers can exploit it via anonymous remote SOAP requests without authentication, making it accessible to anyone with network reach to the endpoints.
OpenCVE Enrichment
Github GHSA