VendorsPing Identitypingfederateall versions
Vulnerabilities

Ping Identity PingFederate

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

14CVEs
CVE-2021-40329
The Authentication API in Ping Identity PingFederate before 10.3 mishandles certain aspects of external password management.
Published 2021-09-27 · Modified
9.8EPSS 0.011
CVE-2023-40545
PingFederate OAuth client_secret_jwt Authentication Bypass
Published 2024-02-06 · Modified
9.8EPSS 0.009
CVE-2023-37283
Authentication Bypass via HTML Form & Identifier First Adapter
Published 2023-10-25 · Modified
9.8EPSS 0.007
CVE-2022-40724
Cross-Site Request Forgery on PingFederate Local Identity Profiles Endpoint.
Published 2023-04-25 · Modified
8.8EPSS 0.002
CVE-2022-40722
Misconfiguration of RSA padding for offline MFA in the PingID Adapter for PingFederate.
Published 2023-04-25 · Modified
7.7EPSS 0.003
CVE-2021-41770
Ping Identity PingFederate before 10.3.1 mishandles pre-parsing validation, leading to an XXE attack that can achieve XML file disclosure.
Published 2021-10-07 · Modified
7.5EPSS 0.010
CVE-2023-39219
Admin Console Denial of Service via Java class enumeration
Published 2023-10-25 · Modified
7.5EPSS 0.006
CVE-2022-23722
PingFederate Password Reset via Authentication API Mishandling
Published 2022-05-02 · Modified
6.5EPSS 0.006
CVE-2021-42000
Ping Identity PingFederate Password Reset and Password Change Mishandling with an authentication policy in parallel reset flows
Published 2022-02-10 · Modified
6.5EPSS 0.005
CVE-2022-40723
Configuration-based MFA Bypass in PingID RADIUS PCV.
Published 2023-04-25 · Modified
6.5EPSS 0.005
CVE-2014-8489
Open redirect vulnerability in startSSO.ping in the SP Endpoints in Ping Identity PingFederate 6.10.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the TargetResource parameter.
Published 2014-12-12 · Modified
6.4EPSS 0.029
CVE-2024-22377
PingFederate Runtime Node Path Traversal
Published 2024-07-09 · Modified
5.3EPSS 0.004
CVE-2023-34085
User Attribute Disclosure via DynamoDB Data Stores
Published 2023-10-25 · Modified
4.3EPSS 0.005
CVE-2024-22477
PingFederate OIDC Policy Management Editor Cross-Site Scripting
Published 2024-07-09 · Modified
4.3EPSS 0.002