← Back

Openidm

openidm

Vendor: Openidm Project • 3 CVEs

CVEs (3)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Openidm Project
1Openidm
May 13, 2026
Apr 9, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
OpenIDM through 4.0.0 and 4.5.0 is vulnerable to reflected cross-site scripting (XSS) attacks within the Admin UI, as demonstrated by the _sortKeys parameter to the authzRoles script under managed/user/.
1Openidm Project
1Openidm
May 13, 2026
Apr 9, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
OpenIDM through 4.0.0 and 4.5.0 is vulnerable to persistent cross-site scripting (XSS) attacks within the Admin UI, as demonstrated by a crafted Managed Object Name.
1Openidm Project
1Openidm
May 13, 2026
Apr 9, 2017
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
In OpenIDM through 4.0.0 before 4.5.0, the info endpoint may leak sensitive information upon a request by the "anonymous" user, as demonstrated by responses with a 200 HTTP status code and a JSON object containing IP add...Show more
In OpenIDM through 4.0.0 before 4.5.0, the info endpoint may leak sensitive information upon a request by the "anonymous" user, as demonstrated by responses with a 200 HTTP status code and a JSON object containing IP address strings. This is related to a missing access-control check in bin/defaults/script/info/login.js.Show less