openam-core is vulnerable to LDAP Injection
86
High Risk
The certificate authentication module builds LDAP search filters from certificate Subject DN attribute values by direct string concatenation without escaping in AMCertStore.setSearchFilter. A client certificate whose Subject DN contains LDAP filter metacharacters injects into the search filter. Injection can match arbitrary directory entries to bypass authentication, enumerate the directory, or trigger expensive wildcard queries. The fix builds the filter with safe RFC 4515-escaped values.
You are affected if you are using a version that falls within the vulnerable range and you enable certificate authentication.
openam-core is vulnerable to LDAP Injection in versions 0.0.1 - 16.1.1.
Upgrade the org.openidentityplatform.openam:openam-core library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant