CVE-2016-10097: XEE
XML External Entity (XXE) Vulnerability in /SSOPOST/metaAlias/%realm%/idpv2 in OpenAM - Access Management 10.1.0 allows remote attackers to read arbitrary files via the SAMLRequest parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-10097?
CVE-2016-10097 is considered a high severity vulnerability due to its potential to allow remote attackers to read arbitrary files.
How do I fix CVE-2016-10097?
To fix CVE-2016-10097, upgrade your OpenAM installation to a version that is not vulnerable to this XML External Entity (XXE) attack.
What type of vulnerability is CVE-2016-10097?
CVE-2016-10097 is an XML External Entity (XXE) vulnerability which can lead to unauthorized file access.
Where is CVE-2016-10097 found?
CVE-2016-10097 is found in ForgeRock OpenAM version 10.1.0 in the /SSOPOST/metaAlias/%realm%/idpv2 endpoint.
What can attackers achieve with CVE-2016-10097?
Attackers can read arbitrary files on the server due to the XML External Entity vulnerability present in CVE-2016-10097.