When a password reset mechanism is configured to use the Authentication API with an Authentication Policy, email One-Time Password, PingID or SMS authentication, an existing user can reset another existing user’s password.
2022-05-02T22:15:09.647
2024-11-21T06:49:10.940
Modified
CVSSv3.1: 6.5 (MEDIUM)
AV:N/AC:M/Au:S/C:N/I:P/A:N
6.8
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | pingidentity | pingfederate | < 9.3.3 | Yes |
Application | pingidentity | pingfederate | < 10.0.12 | Yes |
Application | pingidentity | pingfederate | < 10.1.9 | Yes |
Application | pingidentity | pingfederate | < 10.2.7 | Yes |
Application | pingidentity | pingfederate | < 10.3.4 | Yes |
Application | pingidentity | pingfederate | 9.3.3 | Yes |
Application | pingidentity | pingfederate | 11.0.0 | Yes |