Advisories for Maven/Org.openidentityplatform.openam/Openam-Auth-Oauth2 package

2026

OpenAM Account Takeover via Unverified Password Change in OAuth2 Module

Description An Unverified Password Change (CWE-620) and Use of Weak Credentials (CWE-1391) issue in OpenAM's OAuth2 authentication module silently rewrites a local user's password to the literal string of their username on OAuth2 re-login of an existing account. The default ldapService chain then accepts the username as the password for that user, allowing an unauthenticated attacker to obtain a session via the standard authenticate endpoint with both username and password …