| [Japanese] | 
| JVNDB-2023-001002 | 
| OpenAM Web Policy Agent (OpenAM Consortium Edition) vulnerable to path traversal | 
|
| 
 
OpenAM Web Policy Agent (OpenAM Consortium Edition) provided by OpenAM Consortium parses URLs improperly, leading to a path traversal vulnerability (CWE-22).Furthermore, a crafted URL may be evaluated incorrectly.
 
 OpenAM Consortium reported this vulnerability to JPCERT/CC to notify users of its solution through JVN.
 JPCERT/CC and OpenAM Consortium coordinated under the Information Security Early Warning Partnership.
 | 
|
| 
 
  CVSS V3 Severity:Base Metrics 7.5 (High) [Other]
 
    Attack Vector: NetworkAttack Complexity: LowPrivileges Required: NoneUser Interaction: NoneScope: UnchangedConfidentiality Impact: HighIntegrity Impact: NoneAvailability Impact: None 
  CVSS V2 Severity:Base Metrics 5.0 (Medium) [Other]
 
    Access Vector: NetworkAccess Complexity: LowAuthentication: NoneConfidentiality Impact: PartialIntegrity Impact: NoneAvailability Impact: None 
  
 | 
|
| 
 
	
 | 
| 
 
	OpenAM Consortium
	
		OpenAM Web Policy Agent (OpenAM Consortium Edition) version 4.1.0 | 
| 
 
	
 | 
|
| 
 
Arbitrary files outside the document root on the server may be accessed by an attacker.A protected resource may be accessed via some crafted URL.
 
 | 
|
| 
 
[Apply Patches]Apply the appropriate patches according to the information provided by the developer.
 
 [Apply Workaround]
 Detect and drop malicious requests using WAF (Web Application Firewall) or IPS (Intrusion Prevention System).
 | 
|
| 
 
	OpenAM Consortium
	
 | 
|
| 
 
	Path Traversal(CWE-22) [Other] | 
|
| 
 
	CVE-2023-22320  | 
|
| 
 
	JVN : JVNVU#91740661 National Vulnerability Database (NVD) : CVE-2023-22320  | 
|
| 
 
	[2023/01/11]Web page was published
 
 |