THREAT OPS › Threat News › [GHSA] GHSA-fpmh-vx4h-xc33 (high) — OpenAM Insecure SSO Cookie Initialization
[GHSA] GHSA-fpmh-vx4h-xc33 (high) — OpenAM Insecure SSO Cookie Initialization
GHSA-fpmh-vx4h-xc33 Severity: high CVE: CVE-2026-53660
OpenAM Insecure SSO Cookie Initialization
## Summary
**Description** An Insecure Default Initialization of Resource (CWE-1188) issue in the OpenAM default configuration ships the `iPlanetDirectoryPro` SSO cookie with `HttpOnly=false`. Also, the `iPlanetDirectoryPro` SSO cookie is used as a CSRF token in OAuth/OIDC flows. This affects OpenAM
Indicators of compromise
- CVE-2026-53660cve
Original source: https://github.com/advisories/GHSA-fpmh-vx4h-xc33