Show filters
8 Total Results
Displaying 1-8 of 8
Sort by:
Attacker Value
Unknown
CVE-2025-20059
Disclosure Date: February 20, 2025 (last updated February 21, 2025)
Relative Path Traversal vulnerability in Ping Identity PingAM Java Policy Agent allows Parameter Injection.This issue affects PingAM Java Policy Agent: through 5.10.3, through 2023.11.1, through 2024.9.
0
Attacker Value
Unknown
CVE-2024-23983
Disclosure Date: November 11, 2024 (last updated November 12, 2024)
Improper handling of canonical URL-encoding may lead to bypass not properly constrained by request rules.
0
Attacker Value
Unknown
CVE-2024-23600
Disclosure Date: August 01, 2024 (last updated August 13, 2024)
Improper Input Validation of query search results for private field data in PingIDM (Query Filter module) allows for a potentially efficient brute forcing approach leading to information disclosure.
0
Attacker Value
Unknown
CVE-2024-21832
Disclosure Date: July 09, 2024 (last updated July 10, 2024)
A potential JSON injection attack vector exists in PingFederate REST API data stores using the POST method and a JSON request body.
0
Attacker Value
Unknown
CVE-2023-40702
Disclosure Date: July 09, 2024 (last updated July 10, 2024)
PingOne MFA Integration Kit contains a vulnerability where the skipMFA action can be configured such that user authentication does not require the second factor authentication from the user's existing registered devices. A threat actor might be able to exploit this vulnerability to authenticate as a target user if they have existing knowledge of the target user’s first-factor credentials.
0
Attacker Value
Unknown
CVE-2023-40356
Disclosure Date: July 09, 2024 (last updated July 10, 2024)
PingOne MFA Integration Kit contains a vulnerability related to the Prompt Users to Set Up MFA configuration. Under certain conditions, this configuration could allow for a new MFA device to be paired with a target user account without requiring second-factor authentication from the target’s existing registered devices. A threat actor might be able to exploit this vulnerability to register their own MFA device with a target user’s account if they have existing knowledge of the target user’s first factor credential.
0
Attacker Value
Unknown
CVE-2024-23316
Disclosure Date: May 31, 2024 (last updated June 01, 2024)
HTTP request desynchronization in Ping Identity PingAccess, all versions prior to 8.0.1 affected allows an attacker to send specially crafted http header requests to create a request smuggling condition for proxied requests.
0
Attacker Value
Unknown
CVE-2023-40148
Disclosure Date: April 10, 2024 (last updated April 10, 2024)
Server-side request forgery (SSRF) in PingFederate allows unauthenticated http requests to attack network resources and consume server-side resources via forged HTTP POST requests.
0