Published: November 27, 2017 / Updated: December 8, 2022
Severity Rating: Medium
CVSS Score: 5.0
Affected Products: OpenAM 13.0.0 and later

Description

OpenAM (Open Source Edition) contains a vulnerability in session management.

Impact

A user who can login to the product may change the security questions and reset the login password.

Solution

Patch for this vulnerability has been released by OpenAM Consortium. Apply the patch according to the information provided by OpenAM Consortium.

Workaround

The impact of this vulnerability can be mitigated by disabling the Security Questions function for password resetting.

Reference