Detects OpenIdentityPlatform OpenAM instances before 16.0.6 vulnerable to pre-authentication remote code execution. The jato.clientSession HTTP parameter is deserialized using raw ObjectInputStream without class filtering — a bypass of the CVE-2021-35464 fix that only protected jato.pageSession. Any unauthenticated attacker can execute arbitrary commands.
Is your app exploitable through CVE-2026-33439?
Scan your domain free