CVE-2020-13422: Openiam
High severity, CVSS 8.1. EPSS: 0.9% chance of exploitation in the next 30 days.
OpenIAM before 4.2.0.3 does not verify if a user has permissions to perform /webconsole/rest/api/* administrative actions.
Affected products
- Openiam Openiam: from 4.1.0, before 4.2.0.3 (fixed in 4.2.0.3)
Published 2021-04-06. Last modified 2026-06-17.