In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade org.openidentityplatform.openam:openam-core to version 16.1.1 or higher.
Affected versions of this package are vulnerable to Server-side Request Forgery (SSRF) via the /sessionservice endpoint when authenticated users register URLs for session event notifications without sufficient restriction. An attacker can cause the server to make outbound requests to arbitrary destinations by supplying attacker-controlled URLs, potentially exposing sensitive session-related data.