Horizon Alert
Summary of the vulnerability and why it matters
This advisory concerns a critical vulnerability in Open Access Management (OpenAM) software that allows unauthenticated remote attackers to gain unauthorized access and obtain a normal authenticated session without a password. The issue arises from improper handling of user-supplied input within the MSISDN authentication module, enabling attackers to inject code that manipulates the system's Lightweight Directory Access Protocol (LDAP) search filters. This could allow an attacker to bypass authentication mechanisms and access protected resources.
- Unauthenticated attackers can bypass login.
- Critical access control flaw in authentication module.
- Confirm relevance and exposure for OpenAM.
Attack Path
How an attacker could exploit the issue
An attacker can reach the vulnerable component through the network and trigger the vulnerability without needing any credentials. This occurs within the MSISDN authentication module where an improperly handled phone number input allows for an attacker to craft a malicious LDAP query. Successful exploitation could lead to an attacker gaining normal authenticated access to the system.
- No authentication required.
- Injecting special characters into phone number field.
- Gaining session without password.
Live Threat
Current exploitation, exposure, and threat context
An unauthenticated remote attacker could inject characters into the MSISDN field to manipulate an LDAP search, potentially bypassing authentication and obtaining a normal session. This could occur when the MSISDN module is enabled and accessible within an authentication chain.
- User session access without authentication.
- Attacker manipulates MSISDN input to bypass authentication.
- Compromised user sessions and access to protected resources.
Operational Fix
Recommended remediation, mitigation, and detection steps
Application owners and platform teams are likely responsible for addressing this critical vulnerability in the OpenAM access management solution. The first practical step is to identify all instances of the affected technology, confirm their reachability and business criticality, and then locate the accountable owner to plan remediation based on the identified risk.
- Identify affected OpenAM instances.
- Verify reachability and business criticality.
- Plan remediation with accountable owners.