ADVISORY

HIGH: org.openidentityplatform.openam:openam-core — OpenAM Insecure SSO Cookie Initialization

Summary Description An Insecure Default Initialization of Resource (CWE-1188) issue in the OpenAM default configuration ships the iPlanetDirectoryPro SSO cookie with HttpOnly=false. Also, the iPlanetDirectoryPro SSO cookie is used as a CSRF token in…

Source org.openidentityplatform.openam:openam-corePublished 17h ago · Aug 14, 2026Posted on Bluesky

What we hold

Package
org.openidentityplatform.openam:openam-core
Ecosystem
maven
Severity
HIGH
ID
CVE-2026-53660

Summary Description An Insecure Default Initialization of Resource (CWE-1188) issue in the OpenAM default configuration ships the iPlanetDirectoryPro SSO cookie with HttpOnly=false. Also, the iPlanetDirectoryPro SSO cookie is used as a CSRF token in…

Learning about advisories like this one the day they are published is a separate problem from reading them here. Dependabot alerts, the GitHub Advisory Database API, OSV.dev and npm audit, compared against live responses: how to get an alert when a dependency has a new security advisory.