PT-2025-7534 · Ping Identity · Pingam Java Policy Agent

CVE-2025-20059

·

Publicado

2025-02-20

·

Atualizado

2025-03-01

CVSS v3.1

9.4

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions PingAM Java Policy Agent versions through 5.10.3 PingAM Java Policy Agent versions through 2023.11.1 PingAM Java Policy Agent versions through 2024.9
Description The issue is a Relative Path Traversal vulnerability in Ping Identity PingAM Java Policy Agent, allowing Parameter Injection. This vulnerability affects PingAM Java Policy Agent versions through 5.10.3, through 2023.11.1, and through 2024.9.
Recommendations For versions through 5.10.3, update to a version later than 5.10.3 to resolve the issue. For versions through 2023.11.1, update to a version later than 2023.11.1 to resolve the issue. For versions through 2024.9, update to a version later than 2024.9 to resolve the issue. As a temporary workaround, consider restricting access to vulnerable parameters to minimize the risk of exploitation.

Correção

Relative Path Traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2025-14501
CVE-2025-20059

Produtos afetados

Pingam Java Policy Agent