Junglewise Threat Intelligence

CVE-2025-64099: OpenAM: Using arbitrary OIDC requested claims values in id_token and user_info is allowed

CVE-2025-64099 · Severity: medium · CVSS 4 · Published 2025-11-12

Technologies: org.openidentityplatform.openam:openam-oauth2 (Maven). Vendors: Maven.

Executive brief

OpenAM: Using arbitrary OIDC requested claims values in id_token and user_info is allowed

Affected products

  • Maven org.openidentityplatform.openam:openam-oauth2

Related threats