Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Yasushi Iwakata

Pesquisador deOpen Source Solution Technology Corporation
#17127de 53,635
15.6CVSS total
Vulnerabilidades · 2
Alta
2
PT-2019-8702
7.5
2019-02-13
Forgerock · Openam · CVE-2018-0696
**Name of the Vulnerable Software and Affected Versions** OpenAM (Open Source Edition) versions prior to 13.0 **Description** The issue allows remote authenticated attackers to change security questions and reset the login password. **Recommendations** For versions prior to 13.0, update to version 13.0 or later to resolve the issue.
PT-2017-11575
8.1
2017-11-02
Forgerock · Openam · CVE-2017-10873
**Name of the Vulnerable Software and Affected Versions** OpenAM (Open Source Edition) (affected versions not specified) **Description** The issue allows an attacker to bypass authentication and access unauthorized contents. This affects OpenAM implementations configured as SAML 2.0 IdP, where authentication methods are switched based on AuthnContext requests from the service provider. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.