CVE Database
/

CVE-2018-0696

Back to search

CVE-2018-0696

Published: Feb 13, 2019

Modified: Aug 5, 2024

PUBLISHED

Description

OpenAM (Open Source Edition) 13.0 and later does not properly manage sessions, which allows remote authenticated attackers to change the security questions and reset the login password via unspecified vectors.

VendorProductVersions

OpenAM Consortium

OpenAM

affected
13.0 and later

References

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now