Impact
Prior to 16.1.1, the private_key_jwt client authentication path in OpenAM uses ClientJwksResolverCache without reliably binding a cached jwks_uri resolver and verified assertion to the expected clientID in ClientCredentialsReader. An attacker controlling any registered client with publicly exposed keys, including those obtained through open dynamic registration when enabled, can authenticate as another client whose keys are exposed via its jwks_uri and mint tokens in the target client’s name across realms within the same OpenAM process. The flaw allows the attacker to forge valid tokens on behalf of that client, enabling client impersonation and token forgery. The vulnerability is a weak authentication control identified as CWE‑287.
Affected Systems
The weakness affects the OpenIdentityPlatform OpenAM product. All OpenAM releases prior to version 16.1.1 are vulnerable, including OpenAM 16.0.x and earlier. Upgrading to 16.1.1 or a later release incorporates the fix.
Risk and Exploitability
The CVSS score of 7.6 indicates a high impact when the flaw is abused. The EPSS score of less than 1% reflects a low exploitation probability at the time of analysis, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is remote and requires an adversary to control a legitimate client with exposed public keys, such as one obtained through dynamic client registration. Once that condition is met, the attacker can generate valid tokens in the victim client’s name, potentially accessing sensitive resources or abusing privilege escalation across realms. As the flaw enables unauthorized token issuances, the catastrophic consequences could be significant if the target client has elevated privileges.
OpenCVE Enrichment
Github GHSA