Package Health

openam-oauth2

Signed Maven provenance and no install-time scripts reduce adoption friction. The artifact is a compiled Maven module, so missing README and tests in the bundle are not meaningful gaps.

Latest 16.1.2org.openidentityplatform.openamMavenMaven

84%

Total Score

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

100

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

100

Attestations
Attestations
Measures the presence and validity of package attestations and signatures

100

Are you affected? Scan for Free

Health Score Breakdown

All health scores are okay.

Vulnerabilities

TitleVersionsSeverity
AIKIDO-2026-941486
openam-oauth2 is vulnerable to Server-Side Request Forgery (SSRF) in versions 0.0.1 - 16.1.1.
0.0.1 - 16.1.1
Medium
CVE-2026-62280
org.openidentityplatform.openam:openam-oauth2 is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 13.0.0 - 16.1.1.
13.0.0 - 16.1.1
Medium
CVE-2026-48717
org.openidentityplatform.openam:openam-oauth2 is vulnerable to Improper Authorization in versions 0.0.0 - 16.0.6.
0.0.0 - 16.0.6
Medium
CVE-2026-47426
org.openidentityplatform.openam:openam-oauth2 is vulnerable to Improper Authentication in versions 0.0.0 - 16.0.6.
0.0.0 - 16.0.6
High
CVE-2026-46498
org.openidentityplatform.openam:openam-oauth2 is vulnerable to Authorization Bypass Through User-Controlled Key in versions 0.0.0 - 16.1.1.
0.0.0 - 16.1.1
High

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
org.openidentityplatform.openam:openam-rest
Version *
—
—
org.openidentityplatform.openam:openam-core
Version *
—
—
org.openidentityplatform.openam:openam-scripting
Version *
—
—
org.openidentityplatform.openam:openam-i18n
Version *
—
—
org.openidentityplatform.commons.http-framework:core
Version *
—
—

Weekly Downloads

Info

Last Published
2 months ago
Created
6 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform