OpenIdentityPlatform OpenAM processes the OAuth2 authorization-code grant in the openam-oauth2 component, with the relevant logic in AuthorizationCodeGrantTypeHandler. When the authorization endpoint issues a code with a code_challenge, that code should be bound to the matching code_verifier at the token endpoint. In affected versions, the handler requires code_verifier only when the realm-wide codeVerifierEnforced setting is enabled; when that setting is disabled, verification can be skipped if the caller omits the code_verifier parameter. An explicitly incorrect verifier is still rejected, so the defect is in the missing-parameter path rather than in accepting arbitrary verifiers. The attacker must obtain or intercept an authorization code before it is exchanged for a token; public clients do not require additional client authentication material, while confidential clients require client authentication material or another redemption context that can redeem the code. The patch checks whether the authorization code stored a code_challenge, requires a verifier in that case, and validates the verifier only when the code was actually issued with a challenge.