{"id":"CVE-2025-64099","aliases":[],"url":"https://o3.security/vulnerability/CVE-2025-64099","summary":"OpenAM: Using arbitrary OIDC requested claims values in id_token and user_info is allowed ","details":"### Summary\nIf the \"claims_parameter_supported\" parameter is activated, it is possible through the \"oidc-claims-extension.groovy\" script, to inject the value of choice into a claim contained in the id_token or in the user_info.\nAuthorization function requests do not prevent a claims parameter containing a JSON file to be injected. This JSON file allows users to customize claims returned by the \"id_token\" and \"user_info\" files.\nThis allows for a very wide range of vulnerabilities depending on how clients use claims. For example, if some clients rely on an email field to identify a user, users can choose to entera any email address, and therefore assume any chosen identity.","published":"2025-11-12T21:27:22Z","modified":"2025-11-15T03:34:07.748195Z","cvss":null,"epss":{"score":0.00329,"percentile":0.25564,"asOf":"2026-09-05"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"org.openidentityplatform.openam:openam-oauth2","fixedVersion":"16.0.3"}],"fix":{"url":"https://github.com/OpenIdentityPlatform/OpenAM/commit/4254b34b2b8b4867f2e7fccfac73904213d48510","label":"OpenIdentityPlatform/OpenAM@4254b34"},"references":[{"type":"WEB","url":"https://github.com/OpenIdentityPlatform/OpenAM/security/advisories/GHSA-39hr-239p-fhqc"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-64099"},{"type":"WEB","url":"https://github.com/OpenIdentityPlatform/OpenAM/commit/4254b34b2b8b4867f2e7fccfac73904213d48510"},{"type":"PACKAGE","url":"https://github.com/OpenIdentityPlatform/OpenAM"},{"type":"WEB","url":"https://github.com/OpenIdentityPlatform/OpenAM/releases/tag/16.0.3"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2025-11-15T03:34:07.748195Z"}}