Export CSV

Products

1 vendor
VendorProductsCVEsKEVAvg EPSSWorst Severity
49021.1%CRITICAL

Related CVEs

9
CVE IDDescriptionSeverityCVSSKEVEPSSPublished
CVE-2024-22477A cross-site scripting vulnerability exists in the admin console OIDC Policy Management Editor. The impact is contained to admin console users only.MEDIUM4.37.0%Jul 9, 2024
CVE-2024-22377The deploy directory in PingFederate runtime nodes is reachable to unauthorized users.MEDIUM5.335.1%Jul 9, 2024
CVE-2023-40545Authentication bypass when an OAuth2 Client is using client_secret_jwt as its authentication method on affected 11.3 versions via specially crafted requests. CRITICAL9.8Feb 6, 2024
CVE-2023-36496Delegated Admin Privilege virtual attribute provider plugin, when enabled, allows an authenticated user to elevate their permissions in the Directory Server. HIGH8.8Feb 1, 2024
CVE-2023-39930A first-factor authentication bypass vulnerability exists in the PingFederate with PingID Radius PCV when a MSCHAP authentication request is sent via a maliciously crafted RADIUS client request.CRITICAL9.8Oct 25, 2023
CVE-2023-39231PingFederate using the PingOne MFA adapter allows a new MFA device to be paired without requiring second factor authentication from an existing registered device. A threat actor may be able to exploit this vulnerability to register their own MFA device if they have knowledge of a victim user's first factor credentials.MEDIUM6.5Oct 25, 2023
CVE-2023-39219PingFederate Administrative Console dependency contains a weakness where console becomes unresponsive with crafted Java class loading enumeration requests HIGH7.5Oct 25, 2023
CVE-2023-37283Under a very specific and highly unrecommended configuration, authentication bypass is possible in the PingFederate Identifier First Adapter CRITICAL9.8Oct 25, 2023
CVE-2023-34085When an AWS DynamoDB table is used for user attribute storage, it is possible to retrieve the attributes of another user using a maliciously crafted request MEDIUM4.3Oct 25, 2023