Impact
The vulnerability exists because OpenAM only applies PKCE enforcement to authorization requests with response_type exactly "code". Hybrid flows such as "code token", "code id_token", or "code token id_token" are exempted, allowing issued codes to be used without a bound challenge. An attacker who intercepts a hybrid flow code can redeem it against a public client using any non‑empty code_verifier and obtain tokens. This can compromise user sessions or grant unauthorized access to protected resources.
Affected Systems
OpenIdentityPlatform’s OpenAM is affected when installed at any version earlier than 16.1.3. No other vendors or products are listed as impacted.
Risk and Exploitability
The CVSS score of 7.6 indicates a high‑severity flaw. The EPSS score is not available, but the lack of listing in the CISA KEV catalog suggests that at present the vulnerability is not widely exploited. The likely attack vector is remote, requiring the ability to observe or capture network traffic to obtain an authorization code from a hybrid flow. Once the code is captured, redemption is straightforward and bypasses PKCE checks entirely. Organizations that enable hybrid OAuth flows with public clients face significant risk if they do not apply the 16.1.3 update or otherwise enforce PKCE for all flow types.
OpenCVE Enrichment