| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-c556-q2mh-477v | OpenAM Authenticated Server-Side Request Forgery (SSRF) via `/sessionservice` |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 15 Sep 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 15 Sep 2026 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Openidentityplatform
Openidentityplatform openam |
|
| Vendors & Products |
Openidentityplatform
Openidentityplatform openam |
Tue, 15 Sep 2026 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the /sessionservice addSessionListener operation allows an authenticated user to register an arbitrary notification URL without requiring an administrative or application client token. SessionRequestHandler passes the attacker-controlled destination to the session listener service, causing the OpenAM server to make outbound requests and potentially disclose session-related notification data to an attacker-controlled destination. This issue is fixed in version 16.1.1. | |
| Title | OpenAM Authenticated Server-Side Request Forgery (SSRF) via `/sessionservice` | |
| Weaknesses | CWE-918 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-09-15T14:22:13.301Z
Reserved: 2026-05-05T15:13:47.571Z
Link: CVE-2026-44202
Updated: 2026-09-15T14:22:10.253Z
Status : Received
Published: 2026-09-15T10:17:03.350
Modified: 2026-09-15T15:17:15.337
Link: CVE-2026-44202
No data.
OpenCVE Enrichment
Updated: 2026-09-15T11:45:17Z
Github GHSA