The NT auth module in OpenAM before 14.6.6 allows a “replace Samba username attack.” References https://nvd.nist.gov/vuln/detail/CVE-2022-34298 https://github.com/OpenIdentityPlatform/OpenAM/pull/514 https://github.com/OpenIdentityPlatform/OpenAM/compare/14.6.5…14.6.6 https://github.com/OpenIdentityPlatform/OpenAM/releases/tag/14.6.6 https://github.com/advisories/GHSA-px3r-27qc-hx5g