Description
The NT auth module in OpenAM before 14.6.6 allows a "replace Samba username attack."
Remediation
References
https://github.com/OpenIdentityPlatform/OpenAM/compare/14.6.5...14.6.6
https://github.com/OpenIdentityPlatform/OpenAM/pull/514
https://github.com/OpenIdentityPlatform/OpenAM/releases/tag/14.6.6
Related Vulnerabilities
CVE-2021-46708 Vulnerability in maven package org.webjars.npm:swagger-ui-dist
CVE-2021-21290 Vulnerability in maven package io.netty:netty-transport-native-epoll
CVE-2013-6393 Vulnerability in npm package libyaml
CVE-2023-40014 Vulnerability in npm package @openzeppelin/contracts-upgradeable
CVE-2017-16137 Vulnerability in maven package org.webjars.npm:debug