Vulnerabilities > Pingidentity > Pingfederate > 10.0.15
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-10-25 | CVE-2023-34085 | Unspecified vulnerability in Pingidentity Pingfederate When an AWS DynamoDB table is used for user attribute storage, it is possible to retrieve the attributes of another user using a maliciously crafted request | 4.3 |
2021-10-07 | CVE-2021-41770 | XXE vulnerability in Pingidentity Pingfederate Ping Identity PingFederate before 10.3.1 mishandles pre-parsing validation, leading to an XXE attack that can achieve XML file disclosure. | 7.5 |
2021-09-27 | CVE-2021-40329 | Unspecified vulnerability in Pingidentity Pingfederate The Authentication API in Ping Identity PingFederate before 10.3 mishandles certain aspects of external password management. | 9.8 |