In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade org.openidentityplatform.openam:openam-auth-msisdn to version 16.1.1 or higher.
Affected versions of this package are vulnerable to Insecure Default Initialization of Resource via the MSISDN authentication process. An attacker can gain unauthorized access to arbitrary user sessions by injecting crafted input into the LDAP search filter. This is only exploitable if the MSISDN authentication module is enabled in an authentication chain and reachable through the trusted-gateway list, which allows all traffic by default.