Description
The NT auth module in OpenAM before 14.6.6 allows a "replace Samba username attack."
Remediation
References
https://github.com/OpenIdentityPlatform/OpenAM/compare/14.6.5...14.6.6
https://github.com/OpenIdentityPlatform/OpenAM/pull/514
https://github.com/OpenIdentityPlatform/OpenAM/releases/tag/14.6.6
Related Vulnerabilities
CVE-2021-22696 Vulnerability in maven package org.apache.cxf:cxf-rt-rs-security-oauth2
CVE-2021-21306 Vulnerability in npm package marked
CVE-2019-10759 Vulnerability in maven package org.webjars.npm:safer-eval
CVE-2022-37616 Vulnerability in maven package org.webjars.npm:xmldom
CVE-2021-21623 Vulnerability in maven package org.jenkins-ci.plugins:matrix-auth