Impact
OpenAM’s AuthorizationCodeGrantTypeHandler incorrectly allows a PKCE protection code to be redeemed without a code_verifier when the realm-wide codeVerifierEnforced setting is disabled. An attacker who has intercepted a PKCE‑protected authorization code can omit the required code_verifier and redeem it, receiving access tokens that grant the attacker the authorization level of the original client. Public clients are directly affected; confidential clients can also be exploited if an attacker supplies valid client authentication material or additional redemption context. This bypass of the PKCE protocol provides untrusted access to protected resources and is a classic improper authorization flaw (CWE‑285). The issue is fixed in OpenAM version 16.1.1.
Affected Systems
The vulnerability affects OpenIdentityPlatform’s OpenAM up to version 16.1.0 inclusive. Public clients using OAuth 2.0 with PKCE are directly impacted; confidential clients can also be exploited if an attacker supplies valid client authentication or additional redemption context. The issue is mitigated in OpenAM 16.1.1 and later.
Risk and Exploitability
The CVSS score of 9.1 signals a high severity flaw. EPSS indicates a very low probability of exploitation, and the flaw is not listed in CISA’s KEV catalog. The likely attack path involves an adversary intercepting the authorization code over an insecure channel or through network compromise and then redeeming it without a verifier. However, without interception the flaw remains ineffective, so the risk is contingent on the ability to capture the code.
OpenCVE Enrichment
Github GHSA