User impersonation using SAMLv1.x SSO in Open Access Management
CVE-2023-37471
What is CVE-2023-37471?
OpenAM, an access management solution by ForgeRock, has a vulnerability that allows attackers to exploit improper validation of SAML response signatures during the SAMLv1.x Single Sign-On process. This flaw permits an attacker to impersonate any OpenAM user, including system administrators, by sending a maliciously crafted SAML response to the SAMLPOSTProfileServlet servlet. It is critical for users to upgrade to OpenAM version 14.7.3-SNAPSHOT or later to rectify this issue. For those unable to upgrade, it is advised to comment out the SAMLPOSTProfileServlet from their pom file to mitigate the risk effectively.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
OpenAM < 14.7.3
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
