Vulnerabilities > Pingidentity > Pingfederate > 11.2.5

DATE CVE VULNERABILITY TITLE RISK
2023-10-25 CVE-2023-34085 Unspecified vulnerability in Pingidentity Pingfederate
When an AWS DynamoDB table is used for user attribute storage, it is possible to retrieve the attributes of another user using a maliciously crafted request
network
low complexity
pingidentity
4.3
2023-10-25 CVE-2023-37283 Improper Authentication vulnerability in Pingidentity Pingfederate
Under a very specific and highly unrecommended configuration, authentication bypass is possible in the PingFederate Identifier First Adapter
network
low complexity
pingidentity CWE-287
critical
9.8
2023-10-25 CVE-2023-39219 Resource Exhaustion vulnerability in Pingidentity Pingfederate
PingFederate Administrative Console dependency contains a weakness where console becomes unresponsive with crafted Java class loading enumeration requests
network
low complexity
pingidentity CWE-400
7.5