Impact
The vulnerability is a classic reflected XSS flaw (CWE‑79) that occurs within OpenAM’s OAuth2 authorize endpoint when the display=wap consent page renders request‑derived values through the ConsentRequiredResource and wap/authorize.ftl templates without performing HTML escaping. An attacker can craft a malicious authorization request that, when a user with an active OpenAM session clicks the link, causes the OpenAM origin to execute arbitrary JavaScript. This can lead to session or cookie theft, disclosure of CSRF tokens, or execution of privileged actions on behalf of the victim. The flaw is present in OpenAM versions from 13.0.0 up through, but not including, 16.1.2, and it has been fixed in 16.1.2.
Affected Systems
OpenIdentityPlatform’s OpenAM product is affected. All releases from 13.0.0 up to but not including 16.1.2 contain the flaw. An attacker needs at least one registered OAuth2 client, but does not have to control that client. The issue is fixed in OpenAM 16.1.2.
Risk and Exploitability
The CVSS score of 6.1 indicates moderate severity. The EPSS score of less than 1% shows a very low probability of exploitation at the time of assessment, and the vulnerability is not currently listed in the CISA KEV catalog. Attacks would likely require a user to click a malicious link, making social engineering a necessary component. Given these factors, the overall risk remains moderate but warrants prompt remediation.
OpenCVE Enrichment
Github GHSA