PT-2026-104580 · Forgerock · Openam
CVSS v3.1
6.8
Medium
| Vector | AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
OpenAM versions prior to 16.1.3
Description
The OAuth2 Provider PKCE enforcement is only applied to authorization requests where the
response type is exactly code. Consequently, codes issued via OpenID Connect hybrid flows (such as code token, code id token, or code token id token) are not bound to a challenge. This allows an attacker who intercepts such a code to redeem it for tokens of a public client using any non-empty code verifier. PKCE (Proof Key for Code Exchange) is a security extension used to prevent authorization code injection attacks.Recommendations
Update OpenAM to version 16.1.3 or later.
Fix
Improper Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openam