Impact
The vulnerability allows an authenticated server‑side script author to escape the Groovy sandbox in OpenAM. Prior to version 16.1.1, the GroovySandboxValueFilter permits script authors, such as RealmAdmins who can create or edit scripts, to bypass the default class allow and deny lists. By doing so, they can invoke arbitrary operating‑system commands under the OpenAM application server account, crossing the realm‑scoped administration boundary and compromising the JVM and every realm served by the instance. The weakness is a security misconfiguration (CWE‑693).
Affected Systems
Affected releases are any OpenAM versions earlier than 16.1.1. The issue is fixed in OpenAM 16.1.1, so systems running 16.0.x or earlier are vulnerable. The product is OpenIdentityPlatform’s OpenAM, an access‑management solution.
Risk and Exploitability
The CVSS score of 7.5 indicates a high risk, while the EPSS score of less than 1% suggests a very low current exploitation probability. The vulnerability requires an attacker to have authenticated access and the ability to create or edit scripts, usually through realm‑level administrative rights. Once exploited, the attacker can execute commands at the server level, potentially achieving full system compromise. It is not listed in the CISA KEV catalog.
OpenCVE Enrichment
Github GHSA