Show filters
45 Total Results
Displaying 11-20 of 45
Sort by:
Attacker Value
Unknown
CVE-2022-40724
Disclosure Date: April 25, 2023 (last updated October 08, 2023)
The PingFederate Local Identity Profiles '/pf/idprofile.ping' endpoint is vulnerable to Cross-Site Request Forgery (CSRF) through crafted GET requests.
0
Attacker Value
Unknown
CVE-2022-40723
Disclosure Date: April 25, 2023 (last updated October 08, 2023)
The PingID RADIUS PCV adapter for PingFederate, which supports RADIUS authentication with PingID MFA, is vulnerable to MFA bypass under certain configurations.
0
Attacker Value
Unknown
CVE-2022-40722
Disclosure Date: April 25, 2023 (last updated October 08, 2023)
A misconfiguration of RSA padding implemented in the PingID Adapter for PingFederate to support Offline MFA with PingID mobile authenticators is vulnerable to pre-computed dictionary attacks, leading to a bypass of offline MFA.
0
Attacker Value
Unknown
CVE-2020-25459
Disclosure Date: June 16, 2022 (last updated February 23, 2025)
An issue was discovered in function sync_tree in hetero_decision_tree_guest.py in WeBank FATE (Federated AI Technology Enabler) 0.1 through 1.4.2 allows attackers to read sensitive information during the training process of machine learning joint modeling.
0
Attacker Value
Unknown
CVE-2022-23722
Disclosure Date: May 02, 2022 (last updated February 23, 2025)
When a password reset mechanism is configured to use the Authentication API with an Authentication Policy, email One-Time Password, PingID or SMS authentication, an existing user can reset another existing user’s password.
0
Attacker Value
Unknown
CVE-2022-21822
Disclosure Date: March 17, 2022 (last updated February 23, 2025)
NVIDIA FLARE contains a vulnerability in the admin interface, where an un-authorized attacker can cause Allocation of Resources Without Limits or Throttling, which may lead to cause system unavailable.
0
Attacker Value
Unknown
CVE-2022-26355
Disclosure Date: March 10, 2022 (last updated February 23, 2025)
Citrix Federated Authentication Service (FAS) 7.17 - 10.6 causes deployments that have been configured to store a registration authority certificate's private key in a Trusted Platform Module (TPM) to incorrectly store that key in the Microsoft Software Key Storage Provider (MSKSP). This issue only occurs if PowerShell was used when configuring FAS to store the registration authority certificate’s private key in the TPM. It does not occur if the TPM was not selected for use or if the FAS administration console was used for configuration.
0
Attacker Value
Unknown
CVE-2021-42000
Disclosure Date: February 10, 2022 (last updated February 23, 2025)
When a password reset or password change flow with an authentication policy is configured and the adapter in the reset or change policy supports multiple parallel reset flows, an existing user can reset another existing users password.
0
Attacker Value
Unknown
CVE-2021-41770
Disclosure Date: October 07, 2021 (last updated February 23, 2025)
Ping Identity PingFederate before 10.3.1 mishandles pre-parsing validation, leading to an XXE attack that can achieve XML file disclosure.
0
Attacker Value
Unknown
CVE-2021-40329
Disclosure Date: September 27, 2021 (last updated November 08, 2023)
The Authentication API in Ping Identity PingFederate before 10.3 mishandles certain aspects of external password management.
0