Impact
A pre‑authentication endpoint in OpenAM accepts a CustomCallback XML element whose className field determines which Java class AuthXMLUtils will instantiate without performing any verification that the class implements the required interface. In default configurations the endpoint is exposed without authentication and the vulnerable code also deserializes a Subject value, allowing an attacker to load an arbitrary class, trigger unsafe deserialization, and execute code in the server process. The security setting sunRemoteAuthSecurityEnabled does not mitigate this behavior because its check occurs after the vulnerable parsing.
Affected Systems
OpenIdentityPlatform "OpenAM" versions prior to 16.1.2 are impacted. Any deployment that has not applied the 16.1.2 update or later exposes the /authservice PLL endpoint without authentication and remains vulnerable.
Risk and Exploitability
The CVSS score of 9.8 indicates a critical severity. An EPSS score of roughly 1% suggests that while exploitation is possible, it is not widespread, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is unauthenticated network access to the vulnerable endpoint, making exploitation straightforward for an adversary who can send a crafted XML payload.
OpenCVE Enrichment
Github GHSA