CVE-2018-0696: Osstech Openam

High severity, CVSS 7.5. EPSS: 1.1% chance of exploitation in the next 30 days.

OpenAM (Open Source Edition) 13.0 and later does not properly manage sessions, which allows remote authenticated attackers to change the security questions and reset the login password via unspecified vectors.

Affected products

  • Osstech Openam: from 13.0, up to and including 13.0.0-120

Published 2019-02-13. Last modified 2026-06-17.