GHSA-xq73-fvmr-jvmm

Suggest an improvement
Source
https://github.com/advisories/GHSA-xq73-fvmr-jvmm
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-xq73-fvmr-jvmm/GHSA-xq73-fvmr-jvmm.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-xq73-fvmr-jvmm
Aliases
Published
2026-06-26T17:32:18Z
Modified
2026-06-26T17:56:28Z
Severity
  • 8.7 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
OpenAM Authentication Bypass via MSISDN LDAP Injection
Details

Summary

Description

An LDAP Injection (CWE-90) vulnerability in the MSISDN authentication module allows an unauthenticated, remote attacker to obtain an arbitrary OpenAM session without a password in the default trusted gateway configuration. This impacts OpenAM Community Edition through version 16.0.6. This issue was patched in version 16.1.1.

Impact

OpenAM deployments through version 16.0.6 that have MSISDN enabled are potentially affected. This enables a pre-authentication login bypass for any realm where an MSISDN module instance is enabled in an authentication chain and reachable through the trusted-gateway list, which allows all traffic by default. The request-supplied MSISDN value was concatenated directly into an LDAP search filter. The resulting OpenAM session is a normal authenticated session for the matched user.

Patch

This has been patched in OpenAM Community Edition version 16.1.1. Users are encouraged to update to the latest release.

Database specific
{
    "cwe_ids":  [
        "CWE-1188",
        "CWE-90"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-06-26T17:32:18Z",
    "nvd_published_at":  null,
    "severity":  "HIGH"
}
References

Affected packages

Maven / org.openidentityplatform.openam:openam-auth-msisdn

Package

Name
org.openidentityplatform.openam:openam-auth-msisdn
View open source insights on deps.dev
Purl
pkg:maven/org.openidentityplatform.openam/openam-auth-msisdn

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
16.1.1

Affected versions

14.*
14.5.2
14.5.3
14.5.4
14.6.1
14.6.2
14.6.3
14.6.4
14.6.5
14.6.6
14.7.0
14.7.1
14.7.2
14.7.3
14.7.4
14.8.1
14.8.2
14.8.3
14.8.4
15.*
15.0.0
15.0.1
15.0.2
15.0.3
15.0.4
15.1.0
15.1.1
15.1.2
15.1.3
15.1.4
15.1.5
15.1.6
15.2.0
15.2.1
15.2.2
16.*
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.0.6
16.1.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-xq73-fvmr-jvmm/GHSA-xq73-fvmr-jvmm.json"