Sceawere

Vulnerability Detail

CVE-2026-105121UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

OpenAM Improper Authorization Session Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
4.9
Creation Date
2h ago
Vendor
OpenIdentityPlatform
Product
OpenAM
Attack Type
Improper Authorization
Vector String
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
Attack Complexity
LOW

Narrative and Response

Description

OpenAM before 16.1.3 contains an improper authorization vulnerability that allows delegated administrators to destroy sessions outside their realms because realm checks use the requester's realm. Authenticated accounts holding the iplanet-am-session-destroy-sessions attribute can supply a target session identifier or handle to forcibly log out users in any realm.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "4.9",
  "pubDate": "2026-10-03T14:16:38.997Z",
  "pubdate": "2026-10-03T14:16:38.997Z",
  "executiveSummary": "OpenAM versions prior to 16.1.3 are susceptible to an improper authorization vulnerability that permits delegated administrators to perform unauthorized session termination.\nThe vulnerability stems from a flaw in realm validation logic, where the system fails to correctly verify the boundary between a requester's assigned realm and the target session's realm.\nAn authenticated user possessing the 'iplanet-am-session-destroy-sessions' attribute can exploit this to forcibly terminate sessions belonging to any realm within the deployment.\nThe impact is significant, as it allows for widespread disruption of service by enabling unauthorized account logouts, potentially leading to denial-of-service conditions or the bypass of security session monitoring.\nThis vulnerability requires an authenticated attacker with specific administrative privileges; no remote, unauthenticated access is described.\nThe risk implication involves a total breakdown of multi-tenancy isolation within the OpenAM session management subsystem.",
  "technicalDetails": "The core of this vulnerability lies in the implementation of the session management authorization check within OpenAM. When a request is made to destroy a session, the application is responsible for validating that the requester has administrative authority over the realm in which the target session resides.\nIn affected versions, the authorization logic incorrectly relies on the realm associated with the requester's own session to validate the request. Specifically, the system performs a realm check using the requester's realm context instead of verifying the cross-realm scope of the target session identifier or handle.\nAn attacker must hold the 'iplanet-am-session-destroy-sessions' attribute, which is typically granted to delegated administrators. Once authenticated, the attacker can supply an arbitrary session identifier or handle as a parameter to the session destruction endpoint.\nBecause the underlying validation logic checks if the requester is authorized to perform session destruction within their own realm—rather than validating if the requester has authority over the specific realm of the target session—the application fails to enforce administrative boundaries.\nThe attack flow proceeds as follows: First, the attacker authenticates into the OpenAM instance as an account with the requisite attribute. Second, the attacker captures or identifies a target session ID belonging to a different, restricted, or higher-level realm. Third, the attacker crafts a request to the session management interface, passing the target's session identifier. Finally, the server processes the request, incorrectly validates the requester's permission set based on its own local realm context, and proceeds to invoke the session destruction function on the remote realm's session object, effectively invalidating the target's authentication token.\nThis failure in authorization logic undermines the multi-tenant architecture of OpenAM, as it allows a lower-privileged administrator to affect the availability and security posture of sessions that should be entirely opaque to them. The scope of impact is restricted only by the knowledge of target session handles, which may be discovered through secondary means or concurrent interaction within the environment."
}