CVE-2020-13422: Openiam

High severity, CVSS 8.1. EPSS: 0.9% chance of exploitation in the next 30 days.

OpenIAM before 4.2.0.3 does not verify if a user has permissions to perform /webconsole/rest/api/* administrative actions.

Affected products

  • Openiam Openiam: from 4.1.0, before 4.2.0.3 (fixed in 4.2.0.3)

Published 2021-04-06. Last modified 2026-06-17.