Sploitus

CVE-2025-64099

No indexed exploits for CVE-2025-64099 yet

Open Access Management (OpenAM) is an access management solution. In versions prior to 16.0.0, if the "claims_parameter_supported" parameter is activated, it is possible, thanks to the "oidc-claims-extension.groovy" script, to inject the value of one's choice into a claim contained in the id_token or in the user_info. In the request of an authorize function, a claims parameter containing a JSON file can be injected. This JSON file allows attackers to customize the claims returned by the "id_token" and "user_info" files. This allows for a very wide range of vulnerabilities depending on how clients use claims. For example, if some clients rely on an email field to identify a user, an attacker can choose the email address they want, and therefore assume any identity they choose. Version 16.0.0 fixes the issue.

Affected products
Openam
Fix
Available
CVSS 4.0
9.3 CRITICAL
EPSS
0.3% (25th percentile)
Weakness
CWE-74
NVD status
Deferred
Published
2025-11-12
CVE-2025-64099 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2025-64099 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2025-64099 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.