OpenAM (Open Source Edition) 13.0 and later does not properly manage sessions, which allows remote authenticated attackers to change the security questions and reset the login password via unspecified vectors.
| Software | From | Fixed in |
|---|---|---|
| osstech / openam | 13.0 | 13.0.0-120.x |