| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-xq73-fvmr-jvmm | OpenAM Authentication Bypass via MSISDN LDAP Injection |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 15 Sep 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 15 Sep 2026 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Openidentityplatform
Openidentityplatform openam |
|
| Vendors & Products |
Openidentityplatform
Openidentityplatform openam |
Tue, 15 Sep 2026 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, MSISDNValidation in the MSISDN authentication module concatenates the request-supplied MSISDN value into an LDAP search filter without escaping, while the default empty trusted-gateway list allows all traffic. In a realm where an MSISDN module is enabled in a reachable authentication chain, an unauthenticated remote attacker can inject LDAP filter metacharacters, select an arbitrary matching user, and obtain a normal authenticated OpenAM session without a password. This issue is fixed in version 16.1.1. | |
| Title | OpenAM Authentication Bypass via MSISDN LDAP Injection | |
| Weaknesses | CWE-90 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-09-15T14:23:05.955Z
Reserved: 2026-05-15T19:34:14.012Z
Link: CVE-2026-46619
Updated: 2026-09-15T14:23:00.795Z
Status : Received
Published: 2026-09-15T10:17:04.770
Modified: 2026-09-15T15:17:15.700
Link: CVE-2026-46619
No data.
OpenCVE Enrichment
Updated: 2026-09-15T11:45:17Z
Github GHSA