Executive brief
OpenAM is an identity and access management platform used to provide single sign-on (SSO) capabilities across different domains. A security flaw in its cross-domain component allows an attacker to steal a user's active login session if they can trick the user into clicking a malicious link. This could allow an attacker to impersonate the user and gain unauthorized access to corporate applications and sensitive data.
Technical details
An Information Exposure Through Sent Data (CWE-201) vulnerability exists in the OpenAM Cross-Domain Single Sign-On (CDSSO) servlet. The flaw allows a logged-in user's raw session token to be transmitted via a POST request to an attacker-controlled URL. Exploitation requires the CDSSO component to be enabled (common in multi-domain environments) and requires user interaction, where an authenticated victim is induced to visit a crafted URL. Successful exploitation results in session hijacking. The issue is present in OpenAM Community Edition through version 16.0.6 and was patched in version 16.1.1.
Affected products
- Open Identity Platform OpenAM Community Edition <= 16.0.6
Timeline
- 2026-06-23: disclosed
- 2026-06-23: advisory
- 16.1.1: patched: First patched version