Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
45 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.23% | — | OpenamAI | 3/10/2026 | 6/10/2026 | OpenAM before 16.1.3 contains a server-side request forgery vulnerability that allows attackers able to register or modify OAuth 2.0 clients to make OpenAM fetch internal resources via an unvalidated jwks_uri. Attackers can trigger unauthenticated fetches through client-authentication and ID-token validation to probe… | |
| Aplazada | Media (6.9) | 0.25% | — | OpenamAI | 3/10/2026 | 6/10/2026 | OpenAM before 16.1.3 contains an improper authorization vulnerability that allows delegated administrators to destroy sessions outside their realms because realm checks use the requester's realm. Authenticated accounts holding the iplanet-am-session-destroy-sessions attribute can supply a target session identifier or… | |
| Aplazada | Media (6.9) | 0.26% | — | OpenamAI | 3/10/2026 | 6/10/2026 | OpenAM before 16.1.3 contains an authorization bypass vulnerability in the sessions REST endpoint query operation that allows realm administrators to list sessions of every realm. Attackers holding delegated RealmAdmin privileges can supply a _queryFilter naming another realm to disclose usernames, universal IDs, and… | |
| Aplazada | Alta (7.6) | 0.20% | — | OpenamAI | 3/10/2026 | 6/10/2026 | OpenAM before 16.1.3 applies its OAuth2 Provider PKCE enforcement only to authorization requests whose response_type is exactly code, so codes issued through OpenID Connect hybrid flows (code token, code id_token, code token id_token) carry no bound challenge. An attacker who intercepts such a code can redeem it for a… | |
| Aplazada | Baja (2.3) | 0.10% | — | OpenamAI | 3/10/2026 | 6/10/2026 | OpenAM before 16.1.3 contains an open redirect vulnerability that allows unauthenticated attackers to redirect users by supplying an unverified id_token_hint to the /oauth2/connect/endSession endpoint. Attackers can name any realm client in a forged hint to redirect victims to any registered post-logout URI, enabling… | |
| Aplazada | Media (5.3) | 0.16% | — | Forgerock OpenamAI | 3/10/2026 | 6/10/2026 | OpenAM before 16.1.3 contains an email content injection vulnerability that allows unauthenticated attackers to control notification email wording via the forgotPassword and register actions on /json/{realm}/users. Attackers can supply subject and message fields to send phishing mail from the organisation's configured… | |
| Aplazada | Media (5.1) | 0.15% | — | OpenamAI | 3/10/2026 | 6/10/2026 | OpenAM before 16.1.3 contains a latent cross-site scripting defect that places the SAML message, relay state and target URL unencoded into the load-balancer cookie bounce auto-submit page. If reachable with cookieHashRedirectEnabled set, crafted requests could execute script in the OpenAM origin, though an unrelated… | |
| Aplazada | Alta (8.8) | 0.46% | — | OpenamAI | 3/10/2026 | 6/10/2026 | OpenAM before 16.1.3 contains an unauthenticated arbitrary class instantiation vulnerability in the legacy JAX-RPC SOAP interface that allows remote attackers to load classes without authentication. Attackers can send SOAP requests to /jaxrpc/* with an unverified session identifier and a chosen class name, crashing… | |
| Aplazada | Media (5.3) | 0.17% | — | OpenamAI | 3/10/2026 | 6/10/2026 | OpenAM before 16.1.3 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject script by supplying crafted parameters rendered unencoded on the OAuth2 authorization error page. Attackers can lure victims to a crafted /oauth2/authorize link with repeated parameters to run… | |
| Pendiente de análisis | Crítica (9.8) | 1.1% | — | Forgerock OpenamAI | 15/9/2026 | 25/9/2026 | Open Access Management (OpenAM) is an access management solution. Prior to 16.1.2, the pre-authentication /authservice PLL endpoint accepts a CustomCallback XML element whose className value selects an arbitrary Java class for AuthXMLUtils to load and instantiate without verifying that it implements… | |
| Pendiente de análisis | Media (6.1) | 0.33% | — | Forgerock OpenamAI | 15/9/2026 | 30/9/2026 | Open Access Management (OpenAM) is an access management solution. From 13.0.0 until 16.1.2, the OAuth2 authorize endpoint's display=wap consent page reflects request-derived values through ConsentRequiredResource and wap/authorize.ftl without HTML escaping. An attacker can induce a user with an active OpenAM session… | |
| Pendiente de análisis | Crítica (9.2) | 0.86% | — | Forgerock OpenamAI | 15/9/2026 | 23/9/2026 | Open Access Management (OpenAM) is an access management solution. Prior to 16.1.2, WebAuthnAuthentication.deserialize applies an ObjectInputFilter that allows every serialized object at depth greater than 1 and therefore constrains only an AuthenticatorImpl root object. A pre-authentication attacker can supply a… | |
| Pendiente de análisis | Alta (7.4) | 0.41% | — | Forgerock OpenamAI | 15/9/2026 | 23/9/2026 | Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the default configuration initializes the iPlanetDirectoryPro SSO cookie with HttpOnly disabled and without a protective SameSite default, and OAuth and OpenID Connect consent flows reuse that cookie through CsrfProtection as a CSRF… | |
| Pendiente de análisis | Crítica (9.1) | 0.53% | — | Forgerock OpenamAI | 15/9/2026 | 23/9/2026 | Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, AuthorizationCodeGrantTypeHandler requires a code_verifier only when the realm-wide codeVerifierEnforced setting is enabled, even when an authorization code stores a code_challenge. Because that setting is disabled by default, an… | |
| Pendiente de análisis | Alta (7.6) | 0.55% | — | Forgerock OpenamAI | 15/9/2026 | 23/9/2026 | Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the private_key_jwt client authentication path uses ClientJwksResolverCache without reliably binding a cached jwks_uri resolver and verified assertion to the expected clientID in ClientCredentialsReader. An attacker controlling any… | |
| Pendiente de análisis | Alta (7.5) | 0.48% | — | Forgerock OpenamAI | 15/9/2026 | 23/9/2026 | Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, GroovySandboxValueFilter permits an authenticated server-side script author to escape the scripting sandbox despite the default class allow and deny lists. A user such as a sub-realm RealmAdmin who can create or edit a script in an… | |
| Pendiente de análisis | Alta (7.4) | 0.67% | — | Forgerock OpenamAI | 15/9/2026 | 23/9/2026 | Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the OAuth2 authentication module updates an existing local account with profile attributes that can include userPassword and inetUserStatus, rewriting the password to the username and reactivating disabled accounts. The missing… | |
| Pendiente de análisis | Crítica (9.3) | 0.99% | — | Forgerock OpenamAI | 15/9/2026 | 25/9/2026 | Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, MSISDNValidation in the MSISDN authentication module concatenates the request-supplied MSISDN value into an LDAP search filter without escaping, while the default empty trusted-gateway list allows all traffic. In a realm where an MSISDN… | |
| Pendiente de análisis | Alta (7.6) | 0.41% | — | Forgerock OpenamAI | 15/9/2026 | 23/9/2026 | Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, OAuthTokenStore reads caller-supplied token identifiers from the shared Core Token Store (CTS) without an OAuth-only namespace, and OAuthAdapter accepts a row whose BLOB claims to contain an OAuth token without binding the trusted CTS… | |
| Pendiente de análisis | Alta (7.7) | 0.63% | — | OpenamAI | 15/9/2026 | 30/9/2026 | Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the anonymous Push Notification SNS callback handled by SnsMessageResource falls back to a CTS predicate blob after a messageId expires from the in-memory dispatcher, treats top-level blob keys as Java class names for Class.forName, and… | |
| Pendiente de análisis | Crítica (9.3) | 0.77% | — | Forgerock OpenamAI | 15/9/2026 | 30/9/2026 | Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the Liberty Web Services SOAP receiver permits unauthenticated remote requests to write persistent entries through SOAPReceiver and DiscoveryService into a user's Liberty Discovery store and the shared root-realm Discovery branch. The… | |
| Pendiente de análisis | Crítica (9.2) | 0.69% | — | Forgerock OpenamAI | 15/9/2026 | 23/9/2026 | Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, WebAuthnAuthentication loads a serialized AuthenticatorImpl object graph from the configured userAttribute through loadAuthenticators without an ObjectInputFilter. Exploitation requires the WebAuthn flow to be reachable and an attacker… | |
| Pendiente de análisis | Alta (8.5) | 0.43% | — | Forgerock OpenamAI | 15/9/2026 | 23/9/2026 | Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, SessionRequestHandler in the session management endpoint does not enforce ownership or privilege checks when a low-privileged authenticated user queries session information in deployments using stateful session storage. A requester who… | |
| Pendiente de análisis | Alta (7) | 0.59% | — | Forgerock OpenamAI | 15/9/2026 | 23/9/2026 | Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, certain federation endpoints in a non-default clustered configuration inconsistently encode user-supplied parameters rendered into HTML in the SAML2 cluster cookie-hash redirect path. An unauthenticated attacker can induce a user to… | |
| Pendiente de análisis | Alta (8.3) | 0.59% | — | OpenamAI | 15/9/2026 | 23/9/2026 | Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the OAuth 2.0 and OpenID Connect authorization endpoint does not sufficiently encode user-supplied parameters before FormPostResponse.ftl and checkSession.ftl render them into HTML for the form_post response mode. An unauthenticated… |