CVE-2025-64099 - CVE House
Back to Database
Status published High CVE-2025-64099

OpenAM allows use of arbitrary OIDC requested claims values in id_token and user_info

Vulnerability Description

Open Access Management (OpenAM) is an access management solution. In versions prior to 16.0.0, if the "claims_parameter_supported" parameter is activated, it is possible, thanks to the "oidc-claims-extension.groovy" script, to inject the value of one's choice into a claim contained in the id_token or in the user_info. In the request of an authorize function, a claims parameter containing a JSON file can be injected. This JSON file allows attackers to customize the claims returned by the "id_token" and "user_info" files. This allows for a very wide range of vulnerabilities depending on how clients use claims. For example, if some clients rely on an email field to identify a user, an attacker can choose the email address they want, and therefore assume any identity they choose. Version 16.0.0 fixes the issue.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-64099

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

OpenIdentityPlatform

View all reports →

Affected Software

OpenAM
Vulnerable Versions:
< 16.0.0

Timeline

Official Publish: November 12th, 2025
Last Modified: November 12th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)