Vulnerability Description
OpenAM Consortium Edition version 14.0.0 provided by OpenAM Consortium contains an open redirect vulnerability (CWE-601). When accessing an affected server through some specially crafted URL, the user may be redirected to an arbitrary website.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Osstech | Openam | >= 13.0.0, <= 13.0.0-183 |
Related Weaknesses (CWE)
References
- https://github.com/openam-jp/openam/issues/259Issue TrackingPatchThird Party Advisory
- https://jvn.jp/en/vu/JVNVU99326969/Third Party Advisory
- https://github.com/openam-jp/openam/issues/259Issue TrackingPatchThird Party Advisory
- https://jvn.jp/en/vu/JVNVU99326969/Third Party Advisory
FAQ
What is CVE-2022-31735?
CVE-2022-31735 is a vulnerability with a CVSS score of 6.1 (MEDIUM). OpenAM Consortium Edition version 14.0.0 provided by OpenAM Consortium contains an open redirect vulnerability (CWE-601). When accessing an affected server through some specially crafted URL, the user...
How severe is CVE-2022-31735?
CVE-2022-31735 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-31735?
Check the references section above for vendor advisories and patch information. Affected products include: Osstech Openam.