Show filters
18 Total Results
Displaying 11-18 of 18
Sort by:
Attacker Value
Unknown

CVE-2022-40724

Disclosure Date: April 25, 2023 (last updated October 08, 2023)
The PingFederate Local Identity Profiles '/pf/idprofile.ping' endpoint is vulnerable to Cross-Site Request Forgery (CSRF) through crafted GET requests.
Attacker Value
Unknown

CVE-2022-40723

Disclosure Date: April 25, 2023 (last updated October 08, 2023)
The PingID RADIUS PCV adapter for PingFederate, which supports RADIUS authentication with PingID MFA, is vulnerable to MFA bypass under certain configurations.
Attacker Value
Unknown

CVE-2022-40722

Disclosure Date: April 25, 2023 (last updated October 08, 2023)
A misconfiguration of RSA padding implemented in the PingID Adapter for PingFederate to support Offline MFA with PingID mobile authenticators is vulnerable to pre-computed dictionary attacks, leading to a bypass of offline MFA.
Attacker Value
Unknown

CVE-2022-23722

Disclosure Date: May 02, 2022 (last updated November 08, 2023)
When a password reset mechanism is configured to use the Authentication API with an Authentication Policy, email One-Time Password, PingID or SMS authentication, an existing user can reset another existing user’s password.
Attacker Value
Unknown

CVE-2021-42000

Disclosure Date: February 10, 2022 (last updated October 07, 2023)
When a password reset or password change flow with an authentication policy is configured and the adapter in the reset or change policy supports multiple parallel reset flows, an existing user can reset another existing users password.
Attacker Value
Unknown

CVE-2021-41770

Disclosure Date: October 07, 2021 (last updated February 23, 2025)
Ping Identity PingFederate before 10.3.1 mishandles pre-parsing validation, leading to an XXE attack that can achieve XML file disclosure.
Attacker Value
Unknown

CVE-2021-40329

Disclosure Date: September 27, 2021 (last updated November 08, 2023)
The Authentication API in Ping Identity PingFederate before 10.3 mishandles certain aspects of external password management.
Attacker Value
Unknown

CVE-2014-8489

Disclosure Date: December 12, 2014 (last updated October 05, 2023)
Open redirect vulnerability in startSSO.ping in the SP Endpoints in Ping Identity PingFederate 6.10.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the TargetResource parameter.
0