OpenAM Liberty IDPP Anonymous SOAP Write Access – Privilege Escalation via Unauthenticated Discovery Store Manipulation
OpenAM versions ≤16.0.6 allow unauthenticated attackers to write arbitrary data to the Liberty Discovery store with admin privileges, bypassing identity ACLs. This enables persistent user profile tampering and potential service routing manipulation in deployments consuming Liberty metadata.