CVE-2017-10873: High severity openam vulnerability
OpenAM (Open Source Edition) allows an attacker to bypass authentication and access unauthorized contents via unspecified vectors. Note that this vulnerability affects OpenAM (Open Source Edition) implementations configured as SAML 2.0IdP, and switches authentication methods based on AuthnContext requests sent from the service provider.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2017-10873?
CVE-2017-10873 is categorized as a critical vulnerability due to its potential for unauthorized access through authentication bypass.
How do I fix CVE-2017-10873?
To fix CVE-2017-10873, it is recommended to apply the latest available patches or updates for OpenAM that address this vulnerability.
What versions are affected by CVE-2017-10873?
CVE-2017-10873 affects OpenAM versions from 9.5.5 to 9.5.5-41, 11.0.0 to 11.0.0-112, and 13.0.0 to 13.0.0-73.
What kind of attack can exploit CVE-2017-10873?
CVE-2017-10873 can be exploited by attackers to bypass authentication and gain unauthorized access to protected resources.
Is CVE-2017-10873 related to SAML 2.0 configurations?
Yes, CVE-2017-10873 specifically affects OpenAM implementations configured as SAML 2.0 Identity Providers.