CVE-2017-10873 Information
Feb 14, 2021
cve
Description
OpenAM (Open Source Edition) allows an attacker to bypass authentication and access unauthorized contents via unspecified vectors. Note that this vulnerability affects OpenAM (Open Source Edition) implementations configured as SAML 2.0IdP and switches authentication methods based on AuthnContext requests sent from the service provider.
CVSS Vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Reference
https://jvn.jp/en/jp/JVN79546124/ https://www.cs.themistruct.com/ https://www.osstech.co.jp/support/am2017-2-1-en
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
8.1
Share on: