ZeroHour

CVE-2018-0696

CVSS 3.0
7.5 high
EPSS
1%p62
Published
()
Modified
Description

OpenAM (Open Source Edition) 13.0 and later does not properly manage sessions, which allows remote authenticated attackers to change the security questions and reset the login password via unspecified vectors.

Vendors
osstech
Products
openam
Weakness
CWE-640
Vector
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.