Impact
The vulnerability is an unsafe) in OpenAM’s anonymous Push Notification SNS callback prior to version 16.1.1. When a messageId expires, the callback falls back to a stored CTS predicate blob, treating top-level keys as Java class names and using Class.forName to load them, while deserializing attacker-controlled JSON with Jackson. A low-privileged user with access to a push registration can manipulate the callback after expiry to trigger arbitrary class loading and constructor execution in the OpenAM JVM. This flaw can lead to classpath-dependent process execution, file writes, or denial of service, although verified command execution was not documented on the default classpath. The issue is fixed in OpenAM 16.1.1.
Affected Systems
The affected product is OpenIdentityPlatform’s OpenAM. All releases prior to version 16.1.1 are vulnerable. Any OpenAM installation that has not applied the advisory release 16.1.1 is susceptible.
Risk and Exploitability
The CVSS score of 7.7 signals a high severity vulnerability, but the EPSS score of less than 1% indicates a very low probability of exploitation in the wild. The flaw is not yet listed in CISA’s KEV catalog. The likely attack vector is remote, exploiting the anonymous SNS callback. Successful exploitation would require the attacker to register a push notification, obtain a messageId, wait for expiration, and then send a crafted callback. If the OpenAM JVM’s class the attacker could achieve process execution, corrupt files, or crash the system.
OpenCVE Enrichment
Github GHSA