Description
The NT auth module in OpenAM before 14.6.6 allows a "replace Samba username attack."
Remediation
References
https://github.com/OpenIdentityPlatform/OpenAM/compare/14.6.5...14.6.6
https://github.com/OpenIdentityPlatform/OpenAM/pull/514
https://github.com/OpenIdentityPlatform/OpenAM/releases/tag/14.6.6
Related Vulnerabilities
CVE-2022-26112 Vulnerability in maven package org.apache.pinot:pinot-broker
CVE-2022-31183 Vulnerability in maven package co.fs2:fs2-io_sjs1_2.12
CVE-2022-22965 Vulnerability in maven package org.springframework:spring-webmvc
CVE-2012-4431 Vulnerability in maven package org.apache.tomcat.embed:tomcat-embed-core
CVE-2015-3337 Vulnerability in maven package org.elasticsearch:elasticsearch