Vulnerabilities > Pingidentity > Pingfederate > High

DATE CVE VULNERABILITY TITLE RISK
2023-10-25 CVE-2023-39219 Resource Exhaustion vulnerability in Pingidentity Pingfederate
PingFederate Administrative Console dependency contains a weakness where console becomes unresponsive with crafted Java class loading enumeration requests
network
low complexity
pingidentity CWE-400
7.5
2023-04-25 CVE-2022-40724 Cross-Site Request Forgery (CSRF) vulnerability in Pingidentity Pingfederate 10.3.0/10.3.4/11.0.0
The PingFederate Local Identity Profiles '/pf/idprofile.ping' endpoint is vulnerable to Cross-Site Request Forgery (CSRF) through crafted GET requests.
network
low complexity
pingidentity CWE-352
8.8
2021-10-07 CVE-2021-41770 XXE vulnerability in Pingidentity Pingfederate
Ping Identity PingFederate before 10.3.1 mishandles pre-parsing validation, leading to an XXE attack that can achieve XML file disclosure.
network
low complexity
pingidentity CWE-611
7.5