CVEs (5)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
OpenIAM before 4.2.0.3 does not verify if a user has permissions to perform /webconsole/rest/api/* administrative actions. |
OpenIAM before 4.2.0.3 has Incorrect Access Control for the Create User, Modify User Permissions, and Password Reset actions. |
OpenIAM before 4.2.0.3 allows remote attackers to execute arbitrary code via Groovy Script. |
OpenIAM before 4.2.0.3 allows Directory Traversal in the Batch task. |
OpenIAM before 4.2.0.3 allows XSS in the Add New User feature. |