Skip to content
Noroxi

openiam records

5 published records for vendor openiam.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
1
With a fix record
0%
Median publish → KEV
No record has entered KEV

All records

5 records
  • OpenIAM before 4.2.0.3 allows remote attackers to execute arbitrary code via Groovy Script.

    CriticalCVSS 9.8No exploitEPSS 2%

    openiam · openiamApr 6, 2021

  • OpenIAM before 4.2.0.3 has Incorrect Access Control for the Create User, Modify User Permissions, and Password Reset actions.

    CriticalCVSS 9.8No exploitEPSS 1%

    openiam · openiamApr 6, 2021

  • OpenIAM before 4.2.0.3 does not verify if a user has permissions to perform /webconsole/rest/api/* administrative actions.

    HighCVSS 8.1No exploitEPSS 1%

    openiam · openiamApr 6, 2021

  • OpenIAM before 4.2.0.3 allows XSS in the Add New User feature.

    MediumCVSS 6.1No exploitEPSS 1%

    openiam · openiamApr 6, 2021

  • OpenIAM before 4.2.0.3 allows Directory Traversal in the Batch task.

    MediumCVSS 5.3No exploitEPSS 1%

    openiam · openiamApr 6, 2021