Known Vulnerabilities for products from Openiam
Listed below are 5 of the newest known vulnerabilities associated with the vendor "Openiam".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2020-13422 json | OpenIAM before 4.2.0.3 does not verify if a user has permissions to perform /webconsole/rest/api/* administrative actions. | 8.1 - HIGH | 2021-04-06 | 2022-11-05 |
| CVE-2020-13421 json | OpenIAM before 4.2.0.3 has Incorrect Access Control for the Create User, Modify User Permissions, and Password Reset actions. | 9.8 - CRITICAL | 2021-04-06 | 2022-07-12 |
| CVE-2020-13420 json | OpenIAM before 4.2.0.3 allows remote attackers to execute arbitrary code via Groovy Script. | 9.8 - CRITICAL | 2021-04-06 | 2021-04-08 |
| CVE-2020-13419 json | OpenIAM before 4.2.0.3 allows Directory Traversal in the Batch task. | 5.3 - MEDIUM | 2021-04-06 | 2021-04-08 |
| CVE-2020-13418 json | OpenIAM before 4.2.0.3 allows XSS in the Add New User feature. | 6.1 - MEDIUM | 2021-04-06 | 2021-04-08 |