Skip to main content

Vendor/product archive

pingidentity / pingfederate CVEs

Beta · best-effort

14 CVEs tagged to pingidentity / pingfederate1 Critical, 5 High, 6 Medium, 2 Low, 0 Unrated.

CVE-2024-22477

Published Jul 9, 2024

A cross-site scripting vulnerability exists in the admin console OIDC Policy Management Editor. The impact is contained to admin console users only.

CVSS 1.8 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-40545

Published Feb 6, 2024

Authentication bypass when an OAuth2 Client is using client_secret_jwt as its authentication method on affected 11.3 versions via specially crafted requests.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-39219

Published Oct 25, 2023

PingFederate Administrative Console dependency contains a weakness where console becomes unresponsive with crafted Java class loading enumeration requests

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-37283

Published Oct 25, 2023

Under a very specific and highly unrecommended configuration, authentication bypass is possible in the PingFederate Identifier First Adapter

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2023-34085

Published Oct 25, 2023

When an AWS DynamoDB table is used for user attribute storage, it is possible to retrieve the attributes of another user using a maliciously crafted request

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2022-40724

Published Apr 25, 2023

The PingFederate Local Identity Profiles '/pf/idprofile.ping' endpoint is vulnerable to Cross-Site Request Forgery (CSRF) through crafted GET requests.

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-23722

Published May 2, 2022

When a password reset mechanism is configured to use the Authentication API with an Authentication Policy, email One-Time Password, PingID or SMS authentication, an existing user…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-42000

Published Feb 10, 2022

When a password reset or password change flow with an authentication policy is configured and the adapter in the reset or change policy supports multiple parallel reset flows, an…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-41770

Published Oct 7, 2021

Ping Identity PingFederate before 10.3.1 mishandles pre-parsing validation, leading to an XXE attack that can achieve XML file disclosure.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-40329

Published Sep 27, 2021

The Authentication API in Ping Identity PingFederate before 10.3 mishandles certain aspects of external password management.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2014-8489

Published Dec 12, 2014

Open redirect vulnerability in startSSO.ping in the SP Endpoints in Ping Identity PingFederate 6.10.1 allows remote attackers to redirect users to arbitrary web sites and conduct…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-14 of 14 CVEsPage 1 of 1