Vulnerabilities > Pingidentity > Pingfederate > 10.1.0

DATE CVE VULNERABILITY TITLE RISK
2023-10-25 CVE-2023-34085 Unspecified vulnerability in Pingidentity Pingfederate
When an AWS DynamoDB table is used for user attribute storage, it is possible to retrieve the attributes of another user using a maliciously crafted request
network
low complexity
pingidentity
4.3
2022-05-02 CVE-2022-23722 Improper Authentication vulnerability in Pingidentity Pingfederate
When a password reset mechanism is configured to use the Authentication API with an Authentication Policy, email One-Time Password, PingID or SMS authentication, an existing user can reset another existing user’s password.
network
low complexity
pingidentity CWE-287
6.5
2022-02-10 CVE-2021-42000 Unspecified vulnerability in Pingidentity Pingfederate
When a password reset or password change flow with an authentication policy is configured and the adapter in the reset or change policy supports multiple parallel reset flows, an existing user can reset another existing users password.
network
pingidentity
3.5
2021-10-07 CVE-2021-41770 XXE vulnerability in Pingidentity Pingfederate
Ping Identity PingFederate before 10.3.1 mishandles pre-parsing validation, leading to an XXE attack that can achieve XML file disclosure.
network
low complexity
pingidentity CWE-611
7.5
2021-09-27 CVE-2021-40329 Unspecified vulnerability in Pingidentity Pingfederate
The Authentication API in Ping Identity PingFederate before 10.3 mishandles certain aspects of external password management.
network
low complexity
pingidentity
critical
9.8