Package Health

openam-core

The package has a small runtime dependency surface and a substantial compiled artifact. Repository-level maintenance and licensing could not be verified from the collected Maven metadata.

Latest 16.1.2org.openidentityplatform.openamMavenMaven

82%

Total Score

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

100

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

100

Attestations
Attestations
Measures the presence and validity of package attestations and signatures

100

Are you affected? Scan for Free

Health Score Breakdown

All health scores are okay.

Vulnerabilities

TitleVersionsSeverity
CVE-2026-53660
org.openidentityplatform.openam:openam-core is vulnerable to Sensitive Cookie Without 'HttpOnly' Flag in versions 0.0.0 - 16.1.1.
0.0.0 - 16.1.1
High
AIKIDO-2026-238020
openam-core is vulnerable to LDAP Injection in versions 0.0.1 - 16.1.1.
0.0.1 - 16.1.1
High
AIKIDO-2026-50354
openam-core is vulnerable to Server-Side Request Forgery (SSRF) in versions 0.0.1 - 16.1.1.
0.0.1 - 16.1.1
High
CVE-2026-62379
org.openidentityplatform.openam:openam-core is vulnerable to Improper Control of Generation of Code ('Code Injection') in versions 0.0.0 - 16.1.1.
0.0.0 - 16.1.1
Critical
CVE-2026-45048
org.openidentityplatform.openam:openam-core is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor in versions 0.0.0 - 16.0.6.
0.0.0 - 16.0.6
High

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
org.openidentityplatform.openam:openam-license-servlet
Version *
—
—
org.openidentityplatform.openam:openam-shared
Version *
—
—
org.openidentityplatform.openam:openam-audit-context
Version *
—
—
org.openidentityplatform.openam:openam-audit-core
Version *
—
—
org.openidentityplatform.openam:openam-coretoken
Version *
—
—

Weekly Downloads

Info

Last Published
2 months ago
Created
6 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform