Product:

Pingfederate

(Pingidentity)
Repositories

Unknown:

This might be proprietary software.

#Vulnerabilities 14
Date Id Summary Products Score Patch Annotated
2023-04-25 CVE-2022-40722 A misconfiguration of RSA padding implemented in the PingID Adapter for PingFederate to support Offline MFA with PingID mobile authenticators is vulnerable to pre-computed dictionary attacks, leading to a bypass of offline MFA. Pingfederate, Pingid_adapter_for_pingfederate, Pingid_integration_kit 5.8
2023-04-25 CVE-2022-40723 The PingID RADIUS PCV adapter for PingFederate, which supports RADIUS authentication with PingID MFA, is vulnerable to MFA bypass under certain configurations. Pingfederate, Pingid_integration_kit, Radius_pcv 6.5
2023-04-25 CVE-2022-40724 The PingFederate Local Identity Profiles '/pf/idprofile.ping' endpoint is vulnerable to Cross-Site Request Forgery (CSRF) through crafted GET requests. Pingfederate 8.8
2023-10-25 CVE-2023-34085 When an AWS DynamoDB table is used for user attribute storage, it is possible to retrieve the attributes of another user using a maliciously crafted request Pingfederate 4.3
2023-10-25 CVE-2023-37283 Under a very specific and highly unrecommended configuration, authentication bypass is possible in the PingFederate Identifier First Adapter Pingfederate 9.8
2023-10-25 CVE-2023-39219 PingFederate Administrative Console dependency contains a weakness where console becomes unresponsive with crafted Java class loading enumeration requests Pingfederate 7.5
2024-02-06 CVE-2023-40545 Authentication bypass when an OAuth2 Client is using client_secret_jwt as its authentication method on affected 11.3 versions via specially crafted requests. Pingfederate 9.8
2024-07-09 CVE-2024-22377 The deploy directory in PingFederate runtime nodes is reachable to unauthorized users. Pingfederate 5.3
2024-07-09 CVE-2024-22477 A cross-site scripting vulnerability exists in the admin console OIDC Policy Management Editor. The impact is contained to admin console users only. Pingfederate 4.3
2014-12-12 CVE-2014-8489 Open redirect vulnerability in startSSO.ping in the SP Endpoints in Ping Identity PingFederate 6.10.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the TargetResource parameter. Pingfederate N/A