{"id":"CVE-2022-34298","aliases":["GHSA-px3r-27qc-hx5g"],"url":"https://o3.security/vulnerability/CVE-2022-34298","summary":"NT auth module vulnerability in OpenAM","details":"The NT auth module in OpenAM before 14.6.6 allows a \"replace Samba username attack.\"","published":"2022-06-22T13:18:27Z","modified":"2026-07-15T01:49:20.819713441Z","cvss":{"score":5.3,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"org.openidentityplatform.openam:openam-core","fixedVersion":"14.6.6"}],"fix":{"url":"https://github.com/OpenIdentityPlatform/OpenAM/pull/514","label":"OpenIdentityPlatform/OpenAM#514"},"references":[{"type":"WEB","url":"https://github.com/OpenIdentityPlatform/OpenAM/compare/14.6.5...14.6.6"},{"type":"WEB","url":"https://github.com/OpenIdentityPlatform/OpenAM/releases/tag/14.6.6"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/34xxx/CVE-2022-34298.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-34298"},{"type":"FIX","url":"https://github.com/OpenIdentityPlatform/OpenAM/pull/514"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-15T01:49:20.819713441Z"}}