OpenIdentityPlatform kayıtları
openidentityplatform üreticisine ait 4 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %100
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-287 Improper Authentication1
- CWE-502 Deserialization of Untrusted Data1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
4 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2026-33439Kavram kanıtı | Pre-Authentication Remote Code Execution via `jato.clientSession` Deserialization in OpenAMopenidentityplatform · openam · CWE-502 | Kritik9,3 | — | %8,4 | 7 Nis 2026 |
39İzleyin | CVE-2023-37471İstismar yok | User impersonation using SAMLv1.x SSO in Open Access Managementopenidentityplatform · openam · CWE-287 | Kritik9,8 | — | %1,3 | 20 Tem 2023 |
36İzleyin | CVE-2024-41667Kavram kanıtı | OpenAM FreeMarker template injectionopenidentityplatform · openam · CWE-94 | Yüksek8,8 | — | %3,5 | 24 Tem 2024 |
22İzleyin | CVE-2022-34298Kavram kanıtı | The NT auth module in OpenAM before 14.6.6 allows a "replace Samba username attack."openidentityplatform · openam | Orta5,3 | — | %3,2 | 23 Haz 2022 |
- CVE-2026-3343940Planlayın
Pre-Authentication Remote Code Execution via `jato.clientSession` Deserialization in OpenAM
KritikCVSS 9,3Kavram kanıtıEPSS %8openidentityplatform · openam7 Nis 2026
- CVE-2023-3747139İzleyin
User impersonation using SAMLv1.x SSO in Open Access Management
KritikCVSS 9,8İstismar yokEPSS %1openidentityplatform · openam20 Tem 2023
- CVE-2024-4166736İzleyin
OpenAM FreeMarker template injection
YüksekCVSS 8,8Kavram kanıtıEPSS %4openidentityplatform · openam24 Tem 2024
- CVE-2022-3429822İzleyin
The NT auth module in OpenAM before 14.6.6 allows a "replace Samba username attack."
OrtaCVSS 5,3Kavram kanıtıEPSS %3openidentityplatform · openam23 Haz 2022