PT-2021-9610 · Openiam · Openam

Marek Klon

·

Published

2021-04-06

·

Updated

2022-11-05

·

CVE-2020-13422

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions OpenIAM versions prior to 4.2.0.3
Description The issue concerns a lack of permission verification for users attempting to perform administrative actions through the "/webconsole/rest/api/*" endpoint. This means that users without proper permissions may be able to execute actions they should not have access to.
Recommendations For versions prior to 4.2.0.3, update to version 4.2.0.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the "/webconsole/rest/api/*" endpoint to minimize the risk of exploitation.

Exploit

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2020-13422

Affected Products

Openam