OpenIdentityPlatform OpenAM processes XML requests at the PLL pre-authentication /authservice endpoint. The attacker-controlled className value in a CustomCallback element is used by AuthXMLUtils to load and instantiate an arbitrary Java class without verifying that the class implements DSAMECallbackInterface. In default configurations, the endpoint is reachable without authentication, so attacker-controlled XML can trigger class initialization in the server process.
The same processing path also deserializes a serialized Subject value without a safe class restriction. A suitably crafted value may therefore lead to code execution during deserialization in the OpenAM process. The sunRemoteAuthSecurityEnabled check occurs only after AuthXMLRequest.parseXML has parsed the request and instantiated the named class, so it does not stop the vulnerable processing path. The fix loads the named class without running static initializers, checks for DSAMECallbackInterface before instantiation, and applies an allowlist and limits to Subject deserialization. The available evidence does not identify a specific gadget chain or payload.