OpenAM Web Policy Agent (OpenAM Consortium Edition) provided by OpenAM Consortium parses URLs improperly, leading to a path traversal vulnerability(CWE-22). Furthermore, a crafted URL may be evaluated incorrectly.
| Software | From | Fixed in |
|---|---|---|
| openam / openam | 4.1.0 | 4.1.0.x |