CVE-2023-22320: Openam
High severity, CVSS 7.5. EPSS: 0.7% chance of exploitation in the next 30 days.
OpenAM Web Policy Agent (OpenAM Consortium Edition) provided by OpenAM Consortium parses URLs improperly, leading to a path traversal vulnerability(CWE-22). Furthermore, a crafted URL may be evaluated incorrectly.
Affected products
- Openam Openam: version 4.1.0 only
Published 2023-01-10. Last modified 2026-06-17.