Sceawere

Vulnerability Detail

CVE-2026-105116UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

OpenAM Cross-Site Scripting Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.1
Creation Date
2h ago
Vendor
OpenIdentityPlatform
Product
OpenAM
Attack Type
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

OpenAM before 16.1.3 contains a latent cross-site scripting defect that places the SAML message, relay state and target URL unencoded into the load-balancer cookie bounce auto-submit page. If reachable with cookieHashRedirectEnabled set, crafted requests could execute script in the OpenAM origin, though an unrelated HTTP 500 failure prevents exploitation in released versions.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.1",
  "pubDate": "2026-10-03T14:16:38.257Z",
  "pubdate": "2026-10-03T14:16:38.257Z",
  "executiveSummary": "OpenAM versions prior to 16.1.3 contain a Cross-Site Scripting (XSS) vulnerability residing within the load-balancer cookie bounce auto-submit page.\nThe vulnerability is characterized by improper input sanitization, where SAML messages, relay state parameters, and target URLs are reflected unencoded into the generated HTML response.\nSuccessful exploitation could allow an attacker to execute arbitrary JavaScript within the context of the OpenAM origin, potentially compromising session integrity or facilitating credential theft.\nWhile the vulnerability exists in the source code, current released versions are protected from successful exploitation due to an unrelated HTTP 500 error that interrupts the execution flow of the vulnerable function.\nThe vulnerability requires the 'cookieHashRedirectEnabled' configuration to be set to active.\nThe risk implication is categorized as significant, as the removal or modification of the code path triggering the HTTP 500 error could immediately render the application susceptible to malicious exploitation.",
  "technicalDetails": "The root cause of this vulnerability is an output encoding failure within the component responsible for generating the auto-submit page used for cookie bounce redirects. When a request is processed that triggers this redirect, the application fails to properly sanitize user-supplied input contained in the SAML message, the relay state parameter, and the target URL before embedding them directly into the HTML response document served to the client.\nThe vulnerable mechanism is explicitly tied to the 'cookieHashRedirectEnabled' configuration flag. When this feature is toggled on, the application enters an execution path that constructs an intermediary auto-submit page, intended to ensure proper cookie handling via the load balancer. Due to the lack of context-aware output encoding, an attacker can supply malicious payloads containing JavaScript within these parameters.\nThe attack flow proceeds as follows: An attacker crafts a malicious request targeting the OpenAM endpoint with a URI containing a payload injected into the SAML, relay state, or target URL parameters. Upon receiving the request, the server-side logic processes these parameters and attempts to render the auto-submit HTML page. Because the data is not encoded, the injected script is inserted directly into the document structure. Under normal conditions, the browser would parse and execute the script within the OpenAM origin. However, in the current production implementation, an ancillary HTTP 500 internal server error occurs during the processing of this page, which terminates the request cycle before the malicious payload can be delivered to the client's browser.\nDespite the current mitigation provided by the HTTP 500 error, this constitutes a latent vulnerability. If future software updates, configuration changes, or environment alterations resolve the HTTP 500 error without implementing strict output encoding, the XSS vector will become immediately active. The impact of such an exploit includes the ability for unauthorized actors to perform session hijacking, access sensitive authentication tokens, or redirect users to malicious endpoints. The vulnerability is present in all versions of OpenAM prior to 16.1.3."
}