CVE Published: 10/01/2023 |
CVE Updated: 02/08/2024 |
CVE Year: 2023 Source: jpcert |
Vendor: OpenAM consortium |
Product: OpenAM Web Policy Agent (OpenAM Consortium Edition) Status : PUBLISHED
CVE-2023-22320 Description
OpenAM Web Policy Agent (OpenAM Consortium Edition) provided by OpenAM Consortium parses URLs improperly, leading to a path traversal vulnerability(CWE-22). Furthermore, a crafted URL may be evaluated incorrectly.