Horizon Alert
Summary of the vulnerability and why it matters
A critical vulnerability exists in the Open Access Management solution, specifically within its WebAuthn authentication process. If certain conditions are met, including an attacker's ability to control specific user attributes, a flaw in how data is handled could allow for the execution of malicious code within the application server. The primary concern is to confirm if our deployed instances of this technology are affected and to what extent.
- Malicious code execution via data deserialization.
- Affects a critical access management component.
- Confirm relevance and exposure to this threat.
Attack Path
How an attacker could exploit the issue
An attacker could compromise an OpenAM server by manipulating user attributes, which are then deserialized without proper filtering during the WebAuthn authentication process. This occurs when an attacker can write controlled data to a user attribute, such as through delegated administration or directory access, before the system verifies the WebAuthn assertion. Successful exploitation allows the attacker to execute arbitrary code within the application server's process.
- Requires attacker-controlled data in user attributes.
- Triggered by WebAuthn flow deserializing data.
- Risk of arbitrary code execution.
Live Threat
Current exploitation, exposure, and threat context
This vulnerability could allow an attacker to execute arbitrary code on the application server when a serialized object is loaded without proper filtering. This might occur if an attacker can first control data written to a user attribute through various administrative or provisioning interfaces, and then trigger the WebAuthn authentication flow. The impact is limited to conditions where the WebAuthn flow is reachable and controlled data can be pre-written to the attribute.
- Application server code execution.
- Unfiltered deserialization of controlled data.
- Compromise of application server.
Operational Fix
Recommended remediation, mitigation, and detection steps
Real-world ownership for this vulnerability likely involves application owners responsible for the OpenAM deployment, potentially in collaboration with infrastructure or platform teams managing the application servers. The first practical step is to identify all instances of OpenAM, confirm their reachability and business criticality, and then determine the specific owner for each instance to prioritize remediation.
- Application owners to manage remediation efforts.
- Verify reachability and business criticality first.
- Plan for vendor coordination and updates.