CVE-2018-0696
Published:
Severity Rating:
CVSS Score:
Affected Products:
November 27, 2017
/
Updated: December 8, 2022
Severity Rating:
Medium
CVSS Score:
5.0
Affected Products:
OpenAM 13.0.0 and later
Description
OpenAM (Open Source Edition) contains a vulnerability in session management.
Impact
A user who can login to the product may change the security questions and reset the login password.
Solution
Patch for this vulnerability has been released by OpenAM Consortium. Apply the patch according to the information provided by OpenAM Consortium.
Workaround
The impact of this vulnerability can be mitigated by disabling the Security Questions function for password resetting.