Impact
The flaw resides in OpenAM’s WebAuthnAuthentication.deserialize method, which applies an ObjectInputFilter that allows every serialized object at depth greater than one, constraining only the root AuthenticatorImpl object. A pre‑authentication attacker can supply a userHandle whose serialized graph has a valid AuthenticatorImpl root and a nested gadget class, causing readObject or readResolve execution before cast and assertion verification when a usable gadget is present on the classpath. This bypasses the incomplete remediation for earlier WebAuthn deserialization vulnerabilities, and the vulnerability therefore permits remote code execution on affected servers. The issue is fixed in OpenAM 16.1.2.
Affected Systems
OpenIdentityPlatform OpenAM versions earlier than 16.1.2 are affected. The security fix is included in the 16.1.2 release.
Risk and Exploitability
The CVSS score of 9.2 indicates high severity, and the EPSS score of less than 1% suggests exploitation is currently rare, but the vulnerability was not listed in CISA KEV. The attack vector is a network‑based pre‑authentication request to OpenAM’s WebAuthn endpoint, requiring that a malicious gadget class be available on the Java classpath. Successful exploitation would grant an attacker unrestricted access to the application server and the ability to run arbitrary code.
OpenCVE Enrichment
Github GHSA