[Japanese] | |
JVNDB-2017-000231 | |
OpenAM (Open Source Edition) vulnerable to authentication bypass | |
Overview | |
OpenAM (Open Source Edition) contains an authentication bypass vulnerability. | |
CVSS Severity (What is CVSS?) | |
CVSS V3 Severity:
Base Metrics 6.3 (Medium) [IPA Score]
CVSS V2 Severity:
Base Metrics 6.0 (Medium) [IPA Score]
| |
Affected Products | |
| |
Open Source Solution Technology Corporation | |
This vulnerability may affect the system where OpenAM (all versions of the open source edition) is configured as an SAML 2.0 IdP and is set to switch authentication methods by types of AuthnContext requests that are sent from the service provider. | |
Impact | |
A user may bypass login authentication and access contents for which permissions are not granted. | |
Solution | |
[Apply the Patch] | |
Vendor Information | |
Open Source Solution Technology Corporation | |
CWE (What is CWE?) | |
| |
CVE (What is CVE?) | |
| |
References | |
| |
Revision History | |
|
Date Public | 2017/11/01 |
Date First Published | 2017/11/01 |
Date Last Updated | 2018/03/14 |