Description
The NT auth module in OpenAM before 14.6.6 allows a "replace Samba username attack."
Remediation
References
https://github.com/OpenIdentityPlatform/OpenAM/compare/14.6.5...14.6.6
https://github.com/OpenIdentityPlatform/OpenAM/pull/514
https://github.com/OpenIdentityPlatform/OpenAM/releases/tag/14.6.6
Related Vulnerabilities
CVE-2022-43431 Vulnerability in maven package com.compuware.jenkins:compuware-strobe-measurement
CVE-2022-35961 Vulnerability in maven package org.webjars.npm:openzeppelin__contracts
CVE-2022-41714 Vulnerability in npm package fastest-json-copy
CVE-2021-41164 Vulnerability in npm package ckeditor4
CVE-2021-44878 Vulnerability in maven package org.pac4j:pac4j-core