Vendors · openiam
Products (1)
Recent Vulnerabilities
View all 5 →CVE-2020-13422HIGH 8.1
OpenIAM before 4.2.0.3 does not verify if a user has permissions to perform /webconsole/rest/api/* administrative actions.
CVE-2020-13421CRITICAL 9.8
OpenIAM before 4.2.0.3 has Incorrect Access Control for the Create User, Modify User Permissions, and Password Reset actions.
CVE-2020-13420CRITICAL 9.8
OpenIAM before 4.2.0.3 allows remote attackers to execute arbitrary code via Groovy Script.
CVE-2020-13419MEDIUM 5.3
OpenIAM before 4.2.0.3 allows Directory Traversal in the Batch task.
CVE-2020-13418MEDIUM 6.1
OpenIAM before 4.2.0.3 allows XSS in the Add New User feature.
