Impact
OpenAM’s MSISDN authentication module does not escape the request‑supplied MSISDN value before inserting it into an LDAP search filter, and by default the trusted‑gateway list is empty allowing traffic from any host. Consequently an unauthenticated remote attacker can inject LDAP filter metacharacters into the MSISDN and manipulate the resulting query to match any user. By doing so, the attacker can create a valid OpenAM session without providing a password, thereby bypassing normal authentication controls. The bug is fixed in version 16.1.1.
Affected Systems
OpenIdentityPlatform’s OpenAM product, versions prior to 16.1.1, is affected. The vulnerability exists for any realm that has the MSISDN module enabled within an authentication chain that is reachable from the network. Users of older builds of OpenAM that have not applied the 16.1.1 update are at risk.
Risk and Exploitability
The CVSS score of 9.3 indicates a high severity impact, while the EPSS score of less than 1% suggests a very low current exploitation probability. Because the default trusted‑gateway list is empty, the vulnerability can be triggered by any externally reachable client, so the attack vector is likely remote. The issue is not listed in CISA’s KEV catalogue, meaning there are no confirmed active exploits known to date. Nonetheless, once exploited, the attacker gains the privileges of the matched user, leading to full access to the OpenAM session.
OpenCVE Enrichment
Github GHSA