Insecure Default Initialization of Resource Affecting org.openidentityplatform.openam:openam-auth-msisdn package, versions [,16.1.1)


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JAVA-ORGOPENIDENTITYPLATFORMOPENAM-17675316
  • published29 Jun 2026
  • disclosed26 Jun 2026
  • creditwodzen

Introduced: 26 Jun 2026

NewCVE-2026-46619  (opens in a new tab)
CWE-1188  (opens in a new tab)
CWE-90  (opens in a new tab)

How to fix?

Upgrade org.openidentityplatform.openam:openam-auth-msisdn to version 16.1.1 or higher.

Overview

Affected versions of this package are vulnerable to Insecure Default Initialization of Resource via the MSISDN authentication process. An attacker can gain unauthorized access to arbitrary user sessions by injecting crafted input into the LDAP search filter. This is only exploitable if the MSISDN authentication module is enabled in an authentication chain and reachable through the trusted-gateway list, which allows all traffic by default.

CVSS Base Scores

version 4.0
version 3.1