Skip to content

Commit 9541dc7

Browse files
committed
OpenAM 16.0.4 Released
1 parent ff381a6 commit 9541dc7

File tree

1 file changed

+26
-0
lines changed

1 file changed

+26
-0
lines changed
Lines changed: 26 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,26 @@
1+
---
2+
layout: home
3+
landing-title: "OpenAM 16.0.4 Released"
4+
landing-title2: "OpenAM 16.0.4 Released"
5+
description: OpenAM 16.0.4 includes security updates, bug fixes, and dependency upgrades to address multiple CVEs and improve stability
6+
keywords: 'OpenAM, 16.0.4, release, security update, CVE fixes, ESAPI, Jakarta, Fedlet, Rhino, LZ4, OpenDJ, identity management, access management'
7+
imageurl: 'openam-og.png'
8+
share-buttons: true
9+
---
10+
# OpenAM 16.0.4 Released
11+
[Download](https://github.com/OpenIdentityPlatform/OpenAM/releases/tag/16.0.4)
12+
13+
## What's new
14+
* Updated ESAPI to version 2.7.0.0 with Jakarta classifier for improved security and compatibility
15+
* Fixed Fedlet blank index page issue to restore proper functionality
16+
* Updated OpenDJ dependency to version 5.0.2 for enhanced directory services
17+
* Addressed critical security vulnerabilities:
18+
* [CVE-2025-66453](https://nvd.nist.gov/vuln/detail/CVE-2025-66453) Resolved Rhino high CPU usage and potential DoS vulnerability
19+
* [CVE-2025-12183](https://nvd.nist.gov/vuln/detail/CVE-2025-12183) LZ4 Java Compression has Out-of-bounds memory operations which can cause DoS
20+
* [CVE-2025-66566](https://nvd.nist.gov/vuln/detail/CVE-2025-66566) yawkat LZ4 Java has a possible information leak in Java safe decompressor
21+
22+
Full changeset ([more details](https://github.com/OpenIdentityPlatform/OpenAM/compare/16.0.3...16.0.4))
23+
24+
## Thanks for the contributions
25+
<i id="vharseko"><i>1. <a href="https://github.com/vharseko" target="_blank">vharseko</a></i>
26+
<i id="maximthomas"><i>2. <a href="https://github.com/maximthomas" target="_blank"></a></i>

0 commit comments

Comments
 (0)