CVE-2022-31735: Medium severity openam vulnerability
OpenAM Consortium Edition version 14.0.0 provided by OpenAM Consortium contains an open redirect vulnerability (CWE-601). When accessing an affected server through some specially crafted URL, the user may be redirected to an arbitrary website.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2022-31735?
CVE-2022-31735 has a medium severity due to its potential for misuse through open redirects.
How do I fix CVE-2022-31735?
To fix CVE-2022-31735, ensure that you update OpenAM to a patched version beyond 14.2.0 or 13.0.0.
Which versions of OpenAM are affected by CVE-2022-31735?
CVE-2022-31735 affects OpenAM Consortium Edition versions 14.0.0 to 14.2.0-2 and 13.0.0 up to 13.0.0-183.
What type of vulnerability is CVE-2022-31735?
CVE-2022-31735 is classified as an open redirect vulnerability (CWE-601) allowing attackers to redirect users to arbitrary websites.
What impact does CVE-2022-31735 have?
The impact of CVE-2022-31735 includes potential phishing attacks or redirecting users to malicious sites.