CSNC-2016-002 – Open Redirect in OpenAM

Posted by Alexandre Herzog on Feb 25

#############################################################

#

# COMPASS SECURITY ADVISORY http://www.csnc.ch/en/downloads/advisories.html

#############################################################

#

# CSNC ID: CSNC-2016-002

# Product: OpenAM [1]

# Vendor: ForgeRock

# Subject: Open Redirect

# Risk: Critical

# Effect: Remotely exploitable

# Author:…