Vulnerability index

Browse CVEs

33 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Pingfederate MEDIUM 5.3
CVE-2024-22377

The deploy directory in PingFederate runtime nodes is reachable to unauthorized users.

Fix: after 11.3.4
Fix from $1,600 2024-07-09
Pingfederate CRITICAL 9.8
CVE-2023-40545

Authentication bypass when an OAuth2 Client is using client_secret_jwt as its authentication method on affected 11.3 versions via specially crafted r…

Mitigation only
Fix from $2,300 2024-02-06
Pingdirectory HIGH 8.8
CVE-2023-36496

Delegated Admin Privilege virtual attribute provider plugin, when enabled, allows an authenticated user to elevate their permissions in the Directory…

Fix: after 9.1.0.2
Fix from $1,950 2024-02-01
Pingid Radius Pcv CRITICAL 9.8
CVE-2023-39930

A first-factor authentication bypass vulnerability exists in the PingFederate with PingID Radius PCV when a MSCHAP authentication request is sent via…

Fix: 3.0.3+
Fix from $2,300 2023-10-25
Pingone Mfa Integration Kit MEDIUM 6.5
CVE-2023-39231

PingFederate using the PingOne MFA adapter allows a new MFA device to be paired without requiring second factor authentication from an existing regis…

Mitigation only
Fix from $1,600 2023-10-25
Pingfederate CRITICAL 9.8
CVE-2023-37283

Under a very specific and highly unrecommended configuration, authentication bypass is possible in the PingFederate Identifier First Adapter

Fix: after 11.2.6
Fix from $2,300 2023-10-25
Pingfederate HIGH 7.5
CVE-2023-39219

PingFederate Administrative Console dependency contains a weakness where console becomes unresponsive with crafted Java class loading enumeration req…

Fix: after 11.2.6
Fix from $1,950 2023-10-25
Pingfederate HIGH 8.8
CVE-2022-40724

The PingFederate Local Identity Profiles '/pf/idprofile.ping' endpoint is vulnerable to Cross-Site Request Forgery (CSRF) through crafted GET request…

Fix: after 11.2.2
Fix from $1,950 2023-04-25
Pingfederate MEDIUM 6.5
CVE-2022-40723

The PingID RADIUS PCV adapter for PingFederate, which supports RADIUS authentication with PingID MFA, is vulnerable to MFA bypass under certain confi…

Fix: 2.24 / 3.0.2+
Fix from $1,600 2023-04-25
Desktop MEDIUM 6.1
CVE-2022-40725

PingID Desktop prior to the latest released version 1.7.4 contains a vulnerability that can be exploited to bypass the maximum PIN attempts permitted…

Fix: 1.7.4+
Fix from $1,600 2023-04-25
Pingfederate MEDIUM 5.8
CVE-2022-40722

A misconfiguration of RSA padding implemented in the PingID Adapter for PingFederate to support Offline MFA with PingID mobile authenticators is vuln…

Fix: 2.13.2 / 2.24+
Fix from $1,600 2023-04-25
Self Service Account Manager MEDIUM 6.1
CVE-2018-25084

A vulnerability, which was classified as problematic, has been found in Ping Identity Self-Service Account Manager 1.1.2. Affected by this issue is s…

Patch available
Fix from $1,600 2023-04-10
Pingid Integration For Windows Login HIGH 8.2
CVE-2022-23720

PingID Windows Login prior to 2.8 does not alert or halt operation if it has been provisioned with the full permissions PingID properties file. An IT…

Fix: 2.8+
Fix from $1,950 2022-06-30
Pingid Integration For Windows Login HIGH 8.1
CVE-2022-23718

PingID Windows Login prior to 2.8 uses known vulnerable components that can lead to remote code execution. An attacker capable of achieving a sophist…

Fix: 2.8+
Fix from $1,950 2022-06-30
Pingid Integration For Mac Login HIGH 7.5
CVE-2021-41995

A misconfiguration of RSA in PingID Mac Login prior to 1.1 is vulnerable to pre-computed dictionary attacks, leading to an offline MFA bypass.

Fix: 1.1+
Fix from $1,950 2022-06-30
Pingid Integration For Windows Login MEDIUM 6.4
CVE-2022-23719

PingID Windows Login prior to 2.8 does not authenticate communication with a local Java service used to capture security key requests. An attacker wi…

Fix: 2.8+
Fix from $1,600 2022-06-30
Pingid Integration For Windows Login MEDIUM 5.5
CVE-2022-23717

PingID Windows Login prior to 2.8 is vulnerable to a denial of service condition on local machines when combined with using offline security keys as …

Fix: 2.8+
Fix from $1,600 2022-06-30
Pingid Integration For Windows Login MEDIUM 5.5
CVE-2022-23725

PingID Windows Login prior to 2.8 does not properly set permissions on the Windows Registry entries used to store sensitive API keys under some circu…

Fix: 2.8+
Fix from $1,600 2022-06-30
Pingid Integration For Windows Login HIGH 8.1
CVE-2022-23724

Use of static encryption key material allows forging an authentication token to other users within a tenant organization. MFA may be bypassed by redi…

Fix: 2.4.2+
Fix from $1,950 2022-05-04
Pingone Mfa Integration Kit HIGH 7.7
CVE-2022-23723

An MFA bypass vulnerability exists in the PingFederate PingOne MFA Integration Kit when adapter HTML templates are used as part of an authentication …

Mitigation only
Fix from $1,950 2022-05-02
Pingfederate MEDIUM 6.5
CVE-2022-23722

When a password reset mechanism is configured to use the Authentication API with an Authentication Policy, email One-Time Password, PingID or SMS aut…

Fix: 9.3.3 / 10.0.12+
Fix from $1,600 2022-05-02
Pingid Desktop CRITICAL 9.9
CVE-2021-42001

PingID Desktop prior to 1.7.3 has a misconfiguration in the encryption libraries which can lead to sensitive data exposure. An attacker capable of ex…

Fix: 1.7.3+
Fix from $2,300 2022-04-30
Pingid Integration For Windows Login MEDIUM 5.6
CVE-2021-41992

A misconfiguration of RSA in PingID Windows Login prior to 2.7 is vulnerable to pre-computed dictionary attacks, leading to an offline MFA bypass.

Fix: 2.7+
Fix from $1,600 2022-04-30
Pingfederate MEDIUM 6.5
CVE-2021-42000

When a password reset or password change flow with an authentication policy is configured and the adapter in the reset or change policy supports mult…

Fix: after 10.3.2
Fix from $1,600 2022-02-10
Pingfederate HIGH 7.5
CVE-2021-41770

Ping Identity PingFederate before 10.3.1 mishandles pre-parsing validation, leading to an XXE attack that can achieve XML file disclosure.

Fix: 10.3.1+
Fix from $1,950 2021-10-07
Pingfederate CRITICAL 9.8
CVE-2021-40329

The Authentication API in Ping Identity PingFederate before 10.3 mishandles certain aspects of external password management.

Fix: 10.3+
Fix from $2,300 2021-09-27
Pingaccess MEDIUM 5.3
CVE-2021-31923

Ping Identity PingAccess before 5.3.3 allows HTTP request smuggling via header manipulation.

Fix: 5.3.3+
Fix from $1,600 2021-09-24
Rsa Securid Integration Kit HIGH 7.5
CVE-2021-39270

In Ping Identity RSA SecurID Integration Kit before 3.2, user impersonation can occur.

Fix: 3.2+
Fix from $1,950 2021-08-18
Pingid Integration For Windows Login HIGH 7.8
CVE-2020-25826

PingID Integration for Windows Login before 2.4.2 allows local users to gain privileges by modifying CefSharp.BrowserSubprocess.exe.

Fix: 2.4.2+
Fix from $1,950 2020-09-23
Pingid Ssh Integration CRITICAL 9.8
CVE-2020-10654

Ping Identity PingID SSH before 4.0.14 contains a heap buffer overflow in PingID-enrolled servers. This condition can be potentially exploited into a…

Fix: 4.0.14+
Fix from $2,300 2020-05-13