Impact
Open Access Management (OpenAM) is an access management solution. Prior to version 16.1.1, the OAuthTokenStore reads caller-supplied token identifiers from the shared Core Token Store (CTS) without an OAuth-only namespace, and the OAuthAdapter accepts a row whose BLOB claims to contain an OAuth token without binding the trusted CTS type or verifying integrity. When an attacker can place controlled JSON in the CTS under a known token identifier – for example, via Push Registration followed by an anonymous SNS callback in an enabled realm – they can mint OAuth bearer tokens and OpenID Connect ID tokens with chosen subject, client, realm, and scope. The flaw does not create an OpenAM single sign‑on session or grant console access by itself, but it allows the creation of valid tokens that may be used for unauthorized access to protected resources.
Affected Systems
OpenIdentityPlatform's OpenAM, versions earlier than 16.1.1, can be affected if the Push Registration and anonymous SNS callback features are enabled.
Risk and Exploitability
The CVSS score of 7.6 indicates a medium to high severity vulnerability. With an EPSS score of less than 1 %, the likelihood of exploitation is low at present, and it is not listed in CISA's KEV catalog. The attack would require successful manipulation of the Core Token Store through Push Registration, implying a network-facing vector that could be mitigated by disabling or restricting these functions. If exploited, the attacker can obtain valid access tokens for arbitrary subjects and scopes, potentially accessing protected APIs and resources.
OpenCVE Enrichment
Github GHSA