Show filters
18 Total Results
Displaying 11-18 of 18
Sort by:
Attacker Value
Unknown
CVE-2022-40724
Disclosure Date: April 25, 2023 (last updated October 08, 2023)
The PingFederate Local Identity Profiles '/pf/idprofile.ping' endpoint is vulnerable to Cross-Site Request Forgery (CSRF) through crafted GET requests.
0
Attacker Value
Unknown
CVE-2022-40723
Disclosure Date: April 25, 2023 (last updated October 08, 2023)
The PingID RADIUS PCV adapter for PingFederate, which supports RADIUS authentication with PingID MFA, is vulnerable to MFA bypass under certain configurations.
0
Attacker Value
Unknown
CVE-2022-40722
Disclosure Date: April 25, 2023 (last updated October 08, 2023)
A misconfiguration of RSA padding implemented in the PingID Adapter for PingFederate to support Offline MFA with PingID mobile authenticators is vulnerable to pre-computed dictionary attacks, leading to a bypass of offline MFA.
0
Attacker Value
Unknown
CVE-2022-23722
Disclosure Date: May 02, 2022 (last updated November 08, 2023)
When a password reset mechanism is configured to use the Authentication API with an Authentication Policy, email One-Time Password, PingID or SMS authentication, an existing user can reset another existing user’s password.
0
Attacker Value
Unknown
CVE-2021-42000
Disclosure Date: February 10, 2022 (last updated October 07, 2023)
When a password reset or password change flow with an authentication policy is configured and the adapter in the reset or change policy supports multiple parallel reset flows, an existing user can reset another existing users password.
0
Attacker Value
Unknown
CVE-2021-41770
Disclosure Date: October 07, 2021 (last updated February 23, 2025)
Ping Identity PingFederate before 10.3.1 mishandles pre-parsing validation, leading to an XXE attack that can achieve XML file disclosure.
0
Attacker Value
Unknown
CVE-2021-40329
Disclosure Date: September 27, 2021 (last updated November 08, 2023)
The Authentication API in Ping Identity PingFederate before 10.3 mishandles certain aspects of external password management.
0
Attacker Value
Unknown
CVE-2014-8489
Disclosure Date: December 12, 2014 (last updated October 05, 2023)
Open redirect vulnerability in startSSO.ping in the SP Endpoints in Ping Identity PingFederate 6.10.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the TargetResource parameter.
0