UBUNTU-CVE-2017-10873

Source
https://ubuntu.com/security/CVE-2017-10873
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2017/UBUNTU-CVE-2017-10873.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2017-10873
Upstream
  • CVE-2017-10873
Published
2017-11-02T15:29:00Z
Modified
2025-10-24T04:46:23Z
Severity
  • 8.1 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
  • 8.1 (High) CVSS_V3 - CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
  • Ubuntu - medium
Summary
[none]
Details

OpenAM (Open Source Edition) allows an attacker to bypass authentication and access unauthorized contents via unspecified vectors. Note that this vulnerability affects OpenAM (Open Source Edition) implementations configured as SAML 2.0IdP, and switches authentication methods based on AuthnContext requests sent from the service provider.

References

Affected packages

Ubuntu:16.04:LTS / openam

Package

Name
openam
Purl
pkg:deb/ubuntu/openam@1.4.0-1build6?arch=source&distro=xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.4.0-1build6

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "openam",
            "binary_version": "1.4.0-1build6"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2017/UBUNTU-CVE-2017-10873.json"