CVSS N/A

2019-02-13 19:29:00 2019-02-13 19:29:00

OpenAM (Open Source Edition) 13.0 and later does not properly manage sessions, which allows remote authenticated attackers to change the security questions and reset the login password via unspecified vectors.