Vulnerabilities > Pingidentity > Pingfederate > 11.0.0

DATE CVE VULNERABILITY TITLE RISK
2023-10-25 CVE-2023-34085 Unspecified vulnerability in Pingidentity Pingfederate
When an AWS DynamoDB table is used for user attribute storage, it is possible to retrieve the attributes of another user using a maliciously crafted request
network
low complexity
pingidentity
4.3
2023-04-25 CVE-2022-40724 Cross-Site Request Forgery (CSRF) vulnerability in Pingidentity Pingfederate 10.3.0/10.3.4/11.0.0
The PingFederate Local Identity Profiles '/pf/idprofile.ping' endpoint is vulnerable to Cross-Site Request Forgery (CSRF) through crafted GET requests.
network
low complexity
pingidentity CWE-352
8.8
2022-05-02 CVE-2022-23722 Improper Authentication vulnerability in Pingidentity Pingfederate
When a password reset mechanism is configured to use the Authentication API with an Authentication Policy, email One-Time Password, PingID or SMS authentication, an existing user can reset another existing user’s password.
network
low complexity
pingidentity CWE-287
6.5