Записи pingidentity
43 опубликованных записей вендора pingidentity.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 2
- С записью об исправлении
- 7 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-288 Authentication Bypass Using an Alternate Path or Channel11
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-310 Cryptographic Issues3
- CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')2
- CWE-285 Improper Authorization1
- CWE-287 Improper Authentication1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEОхват bug bounty
Вендор продукта присутствует в публичной программе. Сопоставление по имени; проверьте текст scope в программе.
Все записи
43 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2018-1000134Эксплойта нет | UnboundID LDAP SDK version from commit 801111d8b5c732266a5dbd4b3bb0b6c7b94d7afb up to commit 8471904a02438c03965d21367890276bc25fa5a6, wherepingidentity · ldapsdk · CWE-521 | Критическая9,8 | — | 4,7 % | 16 мар. 2018 г. |
40В плане | CVE-2020-10654Эксплойта нет | Ping Identity PingID SSH before 4.0.14 contains a heap buffer overflow in PingID-enrolled servers.pingidentity · pingid ssh integration · CWE-787 | Критическая9,8 | — | 3,5 % | 13 мая 2020 г. |
39Наблюдать | CVE-2021-40329Эксплойта нет | The Authentication API in Ping Identity PingFederate before 10.3 mishandles certain aspects of external password management.pingidentity · pingfederate | Критическая9,8 | — | 1,1 % | 27 сент. 2021 г. |
39Наблюдать | CVE-2023-40545Эксплойта нет | PingFederate OAuth client_secret_jwt Authentication Bypasspingidentity · pingfederate · CWE-306 | Критическая9,8 | — | 0,9 % | 6 февр. 2024 г. |
39Наблюдать | CVE-2023-37283Эксплойта нет | Authentication Bypass via HTML Form & Identifier First Adapterpingidentity · pingfederate · CWE-287 | Критическая9,8 | — | 0,7 % | 25 окт. 2023 г. |
39Наблюдать | CVE-2023-39930Эксплойта нет | PingFederate PingID Radius PCV Authentication Bypasspingidentity · pingid radius pcv · CWE-288 | Критическая9,8 | — | 0,7 % | 25 окт. 2023 г. |
39Наблюдать | CVE-2021-42001Эксплойта нет | PingID Desktop encryption libraries misconfiguration can lead to sensitive data exposurepingidentity · pingid desktop · CWE-310 | Критическая9,9 | — | 0,5 % | 30 апр. 2022 г. |
35Наблюдать | CVE-2024-23316Эксплойта нет | PingAccess HTTP Request Desynchronization Weaknessping identity · pingaccess · CWE-444 | Высокая8,8 | — | 0,5 % | 31 мая 2024 г. |
35Наблюдать | CVE-2023-36496Эксплойта нет | Delegated Admin Virtual Attribute Provider Privilege Escalationpingidentity · pingdirectory · CWE-269 | Высокая8,8 | — | 0,5 % | 1 февр. 2024 г. |
35Наблюдать | CVE-2022-40724Эксплойта нет | Cross-Site Request Forgery on PingFederate Local Identity Profiles Endpoint.pingidentity · pingfederate · CWE-352 | Высокая8,8 | — | 0,2 % | 25 апр. 2023 г. |
33Наблюдать | CVE-2022-23718Эксплойта нет | PingID Windows Login prior to 2.8 uses known vulnerable components that can lead to remote code executionpingidentity · pingid integration for windows login · CWE-1352 | Высокая8,1 | — | 2,1 % | 30 июн. 2022 г. |
32Наблюдать | CVE-2022-23724Эксплойта нет | PingID Integration for Windows Login MFA Bypasspingidentity · pingid integration for windows login · CWE-288 | Высокая8,1 | — | 0,4 % | 4 мая 2022 г. |
32Наблюдать | CVE-2022-23720Эксплойта нет | PingID Windows Login prior to 2.8 does not alert or halt operation if it has been provisioned with the full permissions PingID properties filepingidentity · pingid integration for windows login · CWE-288 | Высокая8,2 | — | 0,2 % | 30 июн. 2022 г. |
31Наблюдать | CVE-2020-25826Эксплойта нет | PingID Integration for Windows Login before 2.4.2 allows local users to gain privileges by modifying CefSharp.BrowserSubprocess.exe.pingidentity · pingid integration for windows login · CWE-732 | Высокая7,8 | — | 0,4 % | 23 сент. 2020 г. |
30Наблюдать | CVE-2021-41770Эксплойта нет | Ping Identity PingFederate before 10.3.1 mishandles pre-parsing validation, leading to an XXE attack that can achieve XML file disclosure.pingidentity · pingfederate · CWE-611 | Высокая7,5 | — | 1,0 % | 7 окт. 2021 г. |
30Наблюдать | CVE-2022-23723Эксплойта нет | PingFederate PingOneMFA Integration Kit MFA Bypasspingidentity · pingone mfa integration kit · CWE-288 | Высокая7,7 | — | 0,9 % | 2 мая 2022 г. |
30Наблюдать | CVE-2021-41995Эксплойта нет | PingID Mac Login prior to 1.1 vulnerable to pre-computed dictionary attackspingidentity · pingid integration for mac login · CWE-288 | Высокая7,5 | — | 0,8 % | 30 июн. 2022 г. |
30Наблюдать | CVE-2023-39219Эксплойта нет | Admin Console Denial of Service via Java class enumerationpingidentity · pingfederate · CWE-400 | Высокая7,5 | — | 0,6 % | 25 окт. 2023 г. |
30Наблюдать | CVE-2021-39270Эксплойта нет | In Ping Identity RSA SecurID Integration Kit before 3.2, user impersonation can occur.pingidentity · rsa securid integration kit · CWE-346 | Высокая7,5 | — | 0,4 % | 18 авг. 2021 г. |
30Наблюдать | CVE-2023-40702Эксплойта нет | PingOne MFA Integration Kit MFA bypassping identity · pingone mfa integration kit for pingfederate · CWE-290 | Высокая7,7 | — | 0,4 % | 9 июл. 2024 г. |
26Наблюдать | CVE-2014-8489Эксплойта нет | Open redirect vulnerability in startSSO.ping in the SP Endpoints in Ping Identity PingFederate 6.10.1 allows remote attackers to redirect uspingidentity · pingfederate | Средняя6,4 | — | 2,9 % | 12 дек. 2014 г. |
26Наблюдать | CVE-2022-23722Эксплойта нет | PingFederate Password Reset via Authentication API Mishandlingpingidentity · pingfederate · CWE-288 | Средняя6,5 | — | 0,6 % | 2 мая 2022 г. |
26Наблюдать | CVE-2023-39231Эксплойта нет | PingFederate PingOne MFA IK Device Pairing Second Factor Authentication Bypasspingidentity · pingone mfa integration kit · CWE-288 | Средняя6,5 | — | 0,5 % | 25 окт. 2023 г. |
26Наблюдать | CVE-2021-42000Эксплойта нет | Ping Identity PingFederate Password Reset and Password Change Mishandling with an authentication policy in parallel reset flowspingidentity · pingfederate · CWE-285 | Средняя6,5 | — | 0,5 % | 10 февр. 2022 г. |
26Наблюдать | CVE-2022-40723Эксплойта нет | Configuration-based MFA Bypass in PingID RADIUS PCV.pingidentity · pingfederate · CWE-305 | Средняя6,5 | — | 0,5 % | 25 апр. 2023 г. |
- CVE-2018-100013440В плане
UnboundID LDAP SDK version from commit 801111d8b5c732266a5dbd4b3bb0b6c7b94d7afb up to commit 8471904a02438c03965d21367890276bc25fa5a6, where
КритическаяCVSS 9,8Эксплойта нетEPSS 5 %pingidentity · ldapsdk16 мар. 2018 г.
- CVE-2020-1065440В плане
Ping Identity PingID SSH before 4.0.14 contains a heap buffer overflow in PingID-enrolled servers.
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %pingidentity · pingid ssh integration13 мая 2020 г.
- CVE-2021-4032939Наблюдать
The Authentication API in Ping Identity PingFederate before 10.3 mishandles certain aspects of external password management.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %pingidentity · pingfederate27 сент. 2021 г.
- CVE-2023-4054539Наблюдать
PingFederate OAuth client_secret_jwt Authentication Bypass
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %pingidentity · pingfederate6 февр. 2024 г.
- CVE-2023-3728339Наблюдать
Authentication Bypass via HTML Form & Identifier First Adapter
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %pingidentity · pingfederate25 окт. 2023 г.
- CVE-2023-3993039Наблюдать
PingFederate PingID Radius PCV Authentication Bypass
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %pingidentity · pingid radius pcv25 окт. 2023 г.
- CVE-2021-4200139Наблюдать
PingID Desktop encryption libraries misconfiguration can lead to sensitive data exposure
КритическаяCVSS 9,9Эксплойта нетEPSS 1 %pingidentity · pingid desktop30 апр. 2022 г.
- CVE-2024-2331635Наблюдать
PingAccess HTTP Request Desynchronization Weakness
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %ping identity · pingaccess31 мая 2024 г.
- CVE-2023-3649635Наблюдать
Delegated Admin Virtual Attribute Provider Privilege Escalation
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %pingidentity · pingdirectory1 февр. 2024 г.
- CVE-2022-4072435Наблюдать
Cross-Site Request Forgery on PingFederate Local Identity Profiles Endpoint.
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %pingidentity · pingfederate25 апр. 2023 г.
- CVE-2022-2371833Наблюдать
PingID Windows Login prior to 2.8 uses known vulnerable components that can lead to remote code execution
ВысокаяCVSS 8,1Эксплойта нетEPSS 2 %pingidentity · pingid integration for windows login30 июн. 2022 г.
- CVE-2022-2372432Наблюдать
PingID Integration for Windows Login MFA Bypass
ВысокаяCVSS 8,1Эксплойта нетEPSS 0 %pingidentity · pingid integration for windows login4 мая 2022 г.
- CVE-2022-2372032Наблюдать
PingID Windows Login prior to 2.8 does not alert or halt operation if it has been provisioned with the full permissions PingID properties file
ВысокаяCVSS 8,2Эксплойта нетEPSS 0 %pingidentity · pingid integration for windows login30 июн. 2022 г.
- CVE-2020-2582631Наблюдать
PingID Integration for Windows Login before 2.4.2 allows local users to gain privileges by modifying CefSharp.BrowserSubprocess.exe.
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %pingidentity · pingid integration for windows login23 сент. 2020 г.
- CVE-2021-4177030Наблюдать
Ping Identity PingFederate before 10.3.1 mishandles pre-parsing validation, leading to an XXE attack that can achieve XML file disclosure.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %pingidentity · pingfederate7 окт. 2021 г.
- CVE-2022-2372330Наблюдать
PingFederate PingOneMFA Integration Kit MFA Bypass
ВысокаяCVSS 7,7Эксплойта нетEPSS 1 %pingidentity · pingone mfa integration kit2 мая 2022 г.
- CVE-2021-4199530Наблюдать
PingID Mac Login prior to 1.1 vulnerable to pre-computed dictionary attacks
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %pingidentity · pingid integration for mac login30 июн. 2022 г.
- CVE-2023-3921930Наблюдать
Admin Console Denial of Service via Java class enumeration
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %pingidentity · pingfederate25 окт. 2023 г.
- CVE-2021-3927030Наблюдать
In Ping Identity RSA SecurID Integration Kit before 3.2, user impersonation can occur.
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %pingidentity · rsa securid integration kit18 авг. 2021 г.
- CVE-2023-4070230Наблюдать
PingOne MFA Integration Kit MFA bypass
ВысокаяCVSS 7,7Эксплойта нетEPSS 0 %ping identity · pingone mfa integration kit for pingfederate9 июл. 2024 г.
- CVE-2014-848926Наблюдать
Open redirect vulnerability in startSSO.ping in the SP Endpoints in Ping Identity PingFederate 6.10.1 allows remote attackers to redirect us
СредняяCVSS 6,4Эксплойта нетEPSS 3 %pingidentity · pingfederate12 дек. 2014 г.
- CVE-2022-2372226Наблюдать
PingFederate Password Reset via Authentication API Mishandling
СредняяCVSS 6,5Эксплойта нетEPSS 1 %pingidentity · pingfederate2 мая 2022 г.
- CVE-2023-3923126Наблюдать
PingFederate PingOne MFA IK Device Pairing Second Factor Authentication Bypass
СредняяCVSS 6,5Эксплойта нетEPSS 1 %pingidentity · pingone mfa integration kit25 окт. 2023 г.
- CVE-2021-4200026Наблюдать
Ping Identity PingFederate Password Reset and Password Change Mishandling with an authentication policy in parallel reset flows
СредняяCVSS 6,5Эксплойта нетEPSS 1 %pingidentity · pingfederate10 февр. 2022 г.
- CVE-2022-4072326Наблюдать
Configuration-based MFA Bypass in PingID RADIUS PCV.
СредняяCVSS 6,5Эксплойта нетEPSS 1 %pingidentity · pingfederate25 апр. 2023 г.