Sceawere
Vulnerability Detail
CVE-2026-105116UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
OpenAM Cross-Site Scripting Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.1
- Creation Date
- 2h ago
- Vendor
- OpenIdentityPlatform
- Product
- OpenAM
- Attack Type
- Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
OpenAM before 16.1.3 contains a latent cross-site scripting defect that places the SAML message, relay state and target URL unencoded into the load-balancer cookie bounce auto-submit page. If reachable with cookieHashRedirectEnabled set, crafted requests could execute script in the OpenAM origin, though an unrelated HTTP 500 failure prevents exploitation in released versions.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.1",
"pubDate": "2026-10-03T14:16:38.257Z",
"pubdate": "2026-10-03T14:16:38.257Z",
"executiveSummary": "OpenAM versions prior to 16.1.3 contain a Cross-Site Scripting (XSS) vulnerability residing within the load-balancer cookie bounce auto-submit page.\nThe vulnerability is characterized by improper input sanitization, where SAML messages, relay state parameters, and target URLs are reflected unencoded into the generated HTML response.\nSuccessful exploitation could allow an attacker to execute arbitrary JavaScript within the context of the OpenAM origin, potentially compromising session integrity or facilitating credential theft.\nWhile the vulnerability exists in the source code, current released versions are protected from successful exploitation due to an unrelated HTTP 500 error that interrupts the execution flow of the vulnerable function.\nThe vulnerability requires the 'cookieHashRedirectEnabled' configuration to be set to active.\nThe risk implication is categorized as significant, as the removal or modification of the code path triggering the HTTP 500 error could immediately render the application susceptible to malicious exploitation.",
"technicalDetails": "The root cause of this vulnerability is an output encoding failure within the component responsible for generating the auto-submit page used for cookie bounce redirects. When a request is processed that triggers this redirect, the application fails to properly sanitize user-supplied input contained in the SAML message, the relay state parameter, and the target URL before embedding them directly into the HTML response document served to the client.\nThe vulnerable mechanism is explicitly tied to the 'cookieHashRedirectEnabled' configuration flag. When this feature is toggled on, the application enters an execution path that constructs an intermediary auto-submit page, intended to ensure proper cookie handling via the load balancer. Due to the lack of context-aware output encoding, an attacker can supply malicious payloads containing JavaScript within these parameters.\nThe attack flow proceeds as follows: An attacker crafts a malicious request targeting the OpenAM endpoint with a URI containing a payload injected into the SAML, relay state, or target URL parameters. Upon receiving the request, the server-side logic processes these parameters and attempts to render the auto-submit HTML page. Because the data is not encoded, the injected script is inserted directly into the document structure. Under normal conditions, the browser would parse and execute the script within the OpenAM origin. However, in the current production implementation, an ancillary HTTP 500 internal server error occurs during the processing of this page, which terminates the request cycle before the malicious payload can be delivered to the client's browser.\nDespite the current mitigation provided by the HTTP 500 error, this constitutes a latent vulnerability. If future software updates, configuration changes, or environment alterations resolve the HTTP 500 error without implementing strict output encoding, the XSS vector will become immediately active. The impact of such an exploit includes the ability for unauthorized actors to perform session hijacking, access sensitive authentication tokens, or redirect users to malicious endpoints. The vulnerability is present in all versions of OpenAM prior to 16.1.3."
}