In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsLearn about Authorization Bypass Through User-Controlled Key vulnerabilities in an interactive lesson.
Start learningUpgrade org.openidentityplatform.openam:openam-oauth2 to version 16.1.1 or higher.
Affected versions of this package are vulnerable to Authorization Bypass Through User-Controlled Key in the token-read process. An attacker can generate unauthorized OAuth2 bearer tokens with arbitrary user, client, realm, and scope values by injecting attacker-controlled JSON into the shared Core Token Store under a known identifier. This is only exploitable if the OAuth2 Provider service is enabled in a realm and the attacker can register a push notification, allowing them to trigger the vulnerable path.