OpenAM Core Components
88%
Total Score
97
31
97
100
| Title | Versions | Severity |
|---|---|---|
CVE-2026-53660 org.openidentityplatform.openam:openam-core is vulnerable to Sensitive Cookie Without 'HttpOnly' Flag in versions 0.0.0 - 16.1.1. | 0.0.0 - 16.1.1 | High |
AIKIDO-2026-238020 openam-core is vulnerable to LDAP Injection in versions 0.0.1 - 16.1.1. | 0.0.1 - 16.1.1 | High |
AIKIDO-2026-50354 openam-core is vulnerable to Server-Side Request Forgery (SSRF) in versions 0.0.1 - 16.1.1. | 0.0.1 - 16.1.1 | High |
CVE-2026-62379 org.openidentityplatform.openam:openam-core is vulnerable to Improper Control of Generation of Code ('Code Injection') in versions 0.0.0 - 16.1.1. | 0.0.0 - 16.1.1 | Critical |
CVE-2026-45048 org.openidentityplatform.openam:openam-core is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor in versions 0.0.0 - 16.0.6. | 0.0.0 - 16.0.6 | High |
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
org.openidentityplatform.openam:openam-license-servlet Version * | — | — |
org.openidentityplatform.openam:openam-shared Version * | — | — |
org.openidentityplatform.openam:openam-audit-context Version * | — | — |
org.openidentityplatform.openam:openam-audit-core Version * | — | — |
org.openidentityplatform.openam:openam-coretoken Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant