VendorsOpen Identity Platformopenamall versions
Vulnerabilities

Open Identity Platform OpenAM

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2026-33439
Pre-Authentication Remote Code Execution via `jato.clientSession` Deserialization in OpenAM
Published 2026-04-07 · Analyzed
9.8EPSS 0.084
CVE-2023-37471
User impersonation using SAMLv1.x SSO in Open Access Management
Published 2023-07-20 · Modified
9.8EPSS 0.013
CVE-2022-34298
The NT auth module in OpenAM before 14.6.6 allows a "replace Samba username attack."
Published 2022-06-22 · Modified
5.3EPSS 0.032