HIGH: org.openidentityplatform.openam:openam-core — OpenAM Insecure SSO Cookie Initialization
Summary Description An Insecure Default Initialization of Resource (CWE-1188) issue in the OpenAM default configuration ships the iPlanetDirectoryPro SSO cookie with HttpOnly=false. Also, the iPlanetDirectoryPro SSO cookie is used as a CSRF token in…
Source org.openidentityplatform.openam:openam-corePublished 17h ago · Aug 14, 2026Posted on Bluesky

What we hold
- Package
- org.openidentityplatform.openam:openam-core
- Ecosystem
- maven
- Severity
- HIGH
- ID
- CVE-2026-53660
Summary Description An Insecure Default Initialization of Resource (CWE-1188) issue in the OpenAM default configuration ships the iPlanetDirectoryPro SSO cookie with HttpOnly=false. Also, the iPlanetDirectoryPro SSO cookie is used as a CSRF token in…
Learning about advisories like this one the day they are published is a separate problem from reading them here. Dependabot alerts, the GitHub Advisory Database API, OSV.dev and npm audit, compared against live responses: how to get an alert when a dependency has a new security advisory.