OpenIdentityPlatform records
4 published records for vendor openidentityplatform.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-287 Improper Authentication1
- CWE-502 Deserialization of Untrusted Data1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
4 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2026-33439Proof of concept | Pre-Authentication Remote Code Execution via `jato.clientSession` Deserialization in OpenAMopenidentityplatform · openam · CWE-502 | Critical9.3 | — | 8.4% | Apr 7, 2026 |
39Monitor | CVE-2023-37471No exploit | User impersonation using SAMLv1.x SSO in Open Access Managementopenidentityplatform · openam · CWE-287 | Critical9.8 | — | 1.3% | Jul 20, 2023 |
36Monitor | CVE-2024-41667Proof of concept | OpenAM FreeMarker template injectionopenidentityplatform · openam · CWE-94 | High8.8 | — | 3.5% | Jul 24, 2024 |
22Monitor | CVE-2022-34298Proof of concept | The NT auth module in OpenAM before 14.6.6 allows a "replace Samba username attack."openidentityplatform · openam | Medium5.3 | — | 3.2% | Jun 23, 2022 |
- CVE-2026-3343940Plan
Pre-Authentication Remote Code Execution via `jato.clientSession` Deserialization in OpenAM
CriticalCVSS 9.3Proof of conceptEPSS 8%openidentityplatform · openamApr 7, 2026
- CVE-2023-3747139Monitor
User impersonation using SAMLv1.x SSO in Open Access Management
CriticalCVSS 9.8No exploitEPSS 1%openidentityplatform · openamJul 20, 2023
- CVE-2024-4166736Monitor
OpenAM FreeMarker template injection
HighCVSS 8.8Proof of conceptEPSS 4%openidentityplatform · openamJul 24, 2024
- CVE-2022-3429822Monitor
The NT auth module in OpenAM before 14.6.6 allows a "replace Samba username attack."
MediumCVSS 5.3Proof of conceptEPSS 3%openidentityplatform · openamJun 23, 2022