Skip to main content

Vendor archive

pingidentity CVEs

Beta · best-effort

39 CVEs tagged to vendor pingidentity3 Critical, 19 High, 13 Medium, 4 Low, 0 Unrated.

CVE-2024-22477

Published Jul 9, 2024

A cross-site scripting vulnerability exists in the admin console OIDC Policy Management Editor. The impact is contained to admin console users only.

CVSS 1.8 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-40545

Published Feb 6, 2024

Authentication bypass when an OAuth2 Client is using client_secret_jwt as its authentication method on affected 11.3 versions via specially crafted requests.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-36496

Published Feb 1, 2024

Delegated Admin Privilege virtual attribute provider plugin, when enabled, allows an authenticated user to elevate their permissions in the Directory Server.

CVSS 7.7 · High
Vendor/product tagsBeta · best-effort

CVE-2023-39930

Published Oct 25, 2023

A first-factor authentication bypass vulnerability exists in the PingFederate with PingID Radius PCV when a MSCHAP authentication request is sent via a maliciously crafted RADIUS…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-39219

Published Oct 25, 2023

PingFederate Administrative Console dependency contains a weakness where console becomes unresponsive with crafted Java class loading enumeration requests

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-37283

Published Oct 25, 2023

Under a very specific and highly unrecommended configuration, authentication bypass is possible in the PingFederate Identifier First Adapter

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2023-34085

Published Oct 25, 2023

When an AWS DynamoDB table is used for user attribute storage, it is possible to retrieve the attributes of another user using a maliciously crafted request

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2022-40725

Published Apr 25, 2023

PingID Desktop prior to the latest released version 1.7.4 contains a vulnerability that can be exploited to bypass the maximum PIN attempts permitted before the time-based lockout…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2022-40724

Published Apr 25, 2023

The PingFederate Local Identity Profiles '/pf/idprofile.ping' endpoint is vulnerable to Cross-Site Request Forgery (CSRF) through crafted GET requests.

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-25084

Published Apr 10, 2023

A vulnerability, which was classified as problematic, has been found in Ping Identity Self-Service Account Manager 1.1.2. Affected by this issue is some unknown functionality of t…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2022-23726

Published Sep 30, 2022

PingCentral versions prior to listed versions expose Spring Boot actuator endpoints that with administrative authentication return large amounts of sensitive environmental and app…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-23722

Published May 2, 2022

When a password reset mechanism is configured to use the Authentication API with an Authentication Policy, email One-Time Password, PingID or SMS authentication, an existing user…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 39 CVEsPage 1 of 2