Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
45 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (5.3) | 0.41% | — | OpenamAI | 15/9/2026 | 25/9/2026 | Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the /sessionservice addSessionListener operation allows an authenticated user to register an arbitrary notification URL without requiring an administrative or application client token. SessionRequestHandler passes the… | |
| Pendiente de análisis | Alta (7.1) | 0.50% | — | Forgerock OpenamAI | 15/9/2026 | 23/9/2026 | Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, IdentityResourceV1.queryCollection() passes the _queryId parameter from /json/{realm}/users to CrestQuery with escapeQueryId disabled, bypassing protection added for CVE-2021-29156. The unescaped value reaches DJLDAPv3Repo.getFilter(),… | |
| Analizada | Crítica (9.8) | 0.45% | — | Linaro Openamp | 1/5/2026 | 17/6/2026 | OpenAMP v2025.10.0 ELF loader contains an integer overflow vulnerability in firmware image parsing. In elf_loader.c, it performs multiplication of two attacker-controlled 16-bit values from the ELF header without overflow checking. On 32-bit embedded systems (STM32MP1, Zynq, i.MX), large values can cause the product… | |
| Analizada | Crítica (9.3) | 8.4% | 💥 Exploit | Openidentityplatform Openam | 7/4/2026 | 24/7/2026 | Open Access Management (OpenAM) is an access management solution. Prior to 16.0.6, OpenIdentityPlatform OpenAM is vulnerable to pre-authentication Remote Code Execution (RCE) via unsafe Java deserialization of the jato.clientSession HTTP parameter. This bypasses the WhitelistObjectInputStream mitigation that was… | |
| Aplazada | Alta (8.1) | 0.33% | — | OpenamAI | 12/11/2025 | 17/6/2026 | Open Access Management (OpenAM) is an access management solution. In versions prior to 16.0.0, if the "claims_parameter_supported" parameter is activated, it is possible, thanks to the "oidc-claims-extension.groovy" script, to inject the value of one's choice into a claim contained in the id_token or in the user_info.… | |
| Analizada | Baja (2.3) | 0.29% | — | Openam | 2/9/2025 | 17/6/2026 | OpenAM (OpenAM Consortium Edition) contains a vulnerability that may cause it to malfunction as a SAML IdP due to a tampered request.This issue affects OpenAM: from 14.0.0 through 14.0.1. | |
| Aplazada | Alta (8.8) | 3.5% | 💥 Exploit | OpenamAI | 24/7/2024 | 17/6/2026 | OpenAM is an open access management solution. In versions 15.0.3 and prior, the `getCustomLoginUrlTemplate` method in RealmOAuth2ProviderSettings.java is vulnerable to template injection due to its usage of user input. Although the developer intended to implement a custom URL for handling login to override the default… | |
| Modificada | Crítica (9.8) | 1.3% | — | Openidentityplatform Openam | 20/7/2023 | 17/6/2026 | Open Access Management (OpenAM) is an access management solution that includes Authentication, SSO, Authorization, Federation, Entitlements and Web Services Security. OpenAM up to version 14.7.2 does not properly validate the signature of SAML responses received as part of the SAMLv1.x Single Sign-On process.… | |
| Modificada | Alta (7.5) | 0.73% | — | Openam | 10/1/2023 | 17/6/2026 | OpenAM Web Policy Agent (OpenAM Consortium Edition) provided by OpenAM Consortium parses URLs improperly, leading to a path traversal vulnerability(CWE-22). Furthermore, a crafted URL may be evaluated incorrectly. | |
| Modificada | Media (6.1) | 0.55% | — | Osstech Openam | 15/9/2022 | 17/6/2026 | OpenAM Consortium Edition version 14.0.0 provided by OpenAM Consortium contains an open redirect vulnerability (CWE-601). When accessing an affected server through some specially crafted URL, the user may be redirected to an arbitrary website. | |
| Modificada | Media (5.3) | 3.2% | 💥 PoC | Openidentityplatform Openam | 23/6/2022 | 17/6/2026 | The NT auth module in OpenAM before 14.6.6 allows a "replace Samba username attack." | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | Forgerock Access ManagementForgerock Openam | 22/7/2021 | 17/6/2026 | ForgeRock AM server before 7.0 has a Java deserialization vulnerability in the jato.pageSession parameter on multiple pages. The exploitation does not require authentication, and remote code execution can be triggered by sending a single crafted /ccversion/* request to the server. The vulnerability exists due to the… | |
| Modificada | Alta (7.5) | 77% | 💥 Exploit | Forgerock Openam | 25/3/2021 | 17/6/2026 | ForgeRock OpenAM before 13.5.1 allows LDAP injection via the Webfinger protocol. For example, an unauthenticated attacker can perform character-by-character retrieval of password hashes, or retrieve a session token or a private key. | |
| Modificada | Media (6.1) | 0.79% | — | Forgerock Access ManagementForgerock Openam | 19/6/2019 | 17/6/2026 | Auth 2.0 Authorization Server of ForgeRock Access Management (OpenAM) 13.5.0-13.5.1 and Access Management (AM) 5.0.0-5.1.1 does not correctly validate redirect_uri for some invalid requests, which allows attackers to execute a script in the user's browser via reflected XSS. | |
| Modificada | Media (6.1) | 0.79% | — | Forgerock Access ManagementForgerock Openam | 19/6/2019 | 17/6/2026 | OAuth 2.0 Authorization Server of ForgeRock Access Management (OpenAM) 13.5.0-13.5.1 and Access Management (AM) 5.0.0-5.1.1 does not correctly validate redirect_uri for some invalid requests, which allows attackers to perform phishing via an unvalidated redirect. | |
| Modificada | Media (6.1) | 1.1% | — | Osstech Openam | 13/2/2019 | 17/6/2026 | Open redirect vulnerability in OpenAM (Open Source Edition) 13.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a specially crafted page. | |
| Modificada | Alta (7.5) | 1.1% | — | Osstech Openam | 13/2/2019 | 17/6/2026 | OpenAM (Open Source Edition) 13.0 and later does not properly manage sessions, which allows remote authenticated attackers to change the security questions and reset the login password via unspecified vectors. | |
| Modificada | Alta (8.1) | 2.6% | — | Osstech Openam | 2/11/2017 | 17/6/2026 | OpenAM (Open Source Edition) allows an attacker to bypass authentication and access unauthorized contents via unspecified vectors. Note that this vulnerability affects OpenAM (Open Source Edition) implementations configured as SAML 2.0IdP, and switches authentication methods based on AuthnContext requests sent from… | |
| Modificada | Alta (7.5) | 2.5% | — | Forgerock Openam | 2/1/2017 | 17/6/2026 | XML External Entity (XXE) Vulnerability in /SSOPOST/metaAlias/%realm%/idpv2 in OpenAM - Access Management 10.1.0 allows remote attackers to read arbitrary files via the SAMLRequest parameter. | |
| Modificada | Baja (3.5) | 1.1% | — | Forgerock Openam | 14/11/2014 | 17/6/2026 | The Core Server in OpenAM 9.5.3 through 9.5.5, 10.0.0 through 10.0.2, 10.1.0-Xpress, and 11.0.0 through 11.0.2, when deployed on a multi-server network, allows remote authenticated users to cause a denial of service (infinite loop) via a crafted cookie in a request. |