Impact
The vulnerability arises from the default initialization of the iPlanetDirectoryPro SSO cookie. The cookie is created without the HttpOnly flag and without a SameSite default, allowing client side scripts to read it. In OAuth and OpenID Connect consent flows the same cookie is repurposed as a CSRF token. If an attacker can inject same‑origin cross‑site scripting or trick a user into following an attacker‑controlled link, they can read the cookie, replay it to hijack the authenticated session, and grant consent for malicious actions. The underlying weaknesses correspond to CWE-1004, CWE-1188, and CWE-1275.
Affected Systems
OpenIdentityPlatform’s OpenAM component versions older than 16.1.1. The security fix was released with the 16.1.1 update and applies to all OpenAM instances running prior to that release.
Risk and Exploitability
The CVSS score is 7.4, indicating high severity, while the EPSS score is less than 1 percent, reflecting a very low current exploitation probability. The vulnerability is not listed in the CISA KEV catalog, reducing the urgency of immediate exploitation. Attackers would need to first achieve same‑origin XSS or lure a user to a malicious link to read the cookie and reuse it to hijack the session. Because the cookie can be accessed only via client side scripts, network based attacks are not sufficient, making the exploitation path moderately constrained.
OpenCVE Enrichment
Github GHSA