Vulnerabilities > Pingidentity > Pingfederate > Critical

DATE CVE VULNERABILITY TITLE RISK
2024-02-06 CVE-2023-40545 Missing Authentication for Critical Function vulnerability in Pingidentity Pingfederate 11.3.0
Authentication bypass when an OAuth2 Client is using client_secret_jwt as its authentication method on affected 11.3 versions via specially crafted requests.
network
low complexity
pingidentity CWE-306
critical
9.8
2023-10-25 CVE-2023-37283 Improper Authentication vulnerability in Pingidentity Pingfederate
Under a very specific and highly unrecommended configuration, authentication bypass is possible in the PingFederate Identifier First Adapter
network
low complexity
pingidentity CWE-287
critical
9.8
2021-09-27 CVE-2021-40329 Unspecified vulnerability in Pingidentity Pingfederate
The Authentication API in Ping Identity PingFederate before 10.3 mishandles certain aspects of external password management.
network
low complexity
pingidentity
critical
9.8