Security restrictions bypass in OpenAM - CVE-2018-0696
Published: February 15, 2019
OpenAM
OpenAM Consortium
Description
The vulnerability allows a remote authenticated attacker to bypass security restrictions.
The vulnerability exists due to due to improper session management. A remote attacker can modify security questions and then change existing users’ passwords that may allow to cause a denial of service (DoS) condition or conduct further attacks.